Security Configuration
ACL Configuration
\[Command] show acl table \[ table name ] \[Purpose] Show existing ACL tables \[Parameter] \[View] System view \[Use Cases] \[Command] show acl rule \[ table name ] \[ rule id ] \[Purpose] Show existing ACL rules \[Parameter] \[View] System view \[Use Cases] \[Command ] show counters acl \[ acl-table-name ] \[ rule-id ] \[Purpose] Show ACL hit count \[Parameter] \[View] System view \[Notes] Allows multiple tables and rules to be entered, either as individual tables or as table + rule. Table and table are separated by ",", rule and rule are separated by ","; table and rule are separated by spaces.
Network Traffic Security Inspection
\[Command] show stateful-packet-inspection status \[Purpose] Display the enable status of SPI inspection, including the enable status for SPI inspection of four message types TCP, UDP, ICMP, and other. \[View] System view \[Use Cases] \[Command] show stateful-packet-inspection timeout { global|user-defined } \[Purpose] Display the timeout time for SPI configuration, default for unconfigured protocol types \[Parameter] \[View] System view \[Use Cases] \[Command] stateful-packet-inspection enable { tcp|udp|icmp|other } \[Purpose] Enable SPI to monitor sessions for different protocol types.
DHCP Snooping Configuration
\[Command] show dhcp snooping config \[Purpose] View DHCP snooping related configuration status \[View] System view \[Use Cases] \[Command] show snooping table \[Purpose] View all snooping table entry details \[View] System view \[Notes] Snooping table entries include those learned by DHCP Snooping and ND Snooping. When this feature is enabled, the device can sync snooping table entries from other devices configured as neighbors, ensuring consistency across the network.
ND Snooping Configuration
\[Command] show nd snooping config \[Purpose] View ND snooping configuration \[View] System view \[Use Cases] \[Command] nd snooping enable no nd snooping enable \[Purpose] Enable ND snooping function globally \[View] System configuration view, Interface view, VLAN Interface view \[Notes] After ND Snooping is enabled on the device, the interface with ND Snooping enabled will learn the ND Snooping table entry when it receives NS packets from DAD. If the device is enabled with SAVI and IPSGv6, the ND and DHCPv6 packets will be matched according to the ND Snooping table entry.
User Binding Rule Configuration
\[Command] show user-bind counter \[ interface-name ] clear user-bind counter \[Purpose] Show packet loss statistics for packets inspection function \[View] System view \[Notes] Statistics of packets dropped due to unhit table entries after enabling IPSG/IPSGv6/ARP detection/SAVI function. \[Use Cases] \[Command] show user-bind rule \[Purpose] View static binding table information \[View] System view \[Use Cases] \[Command] show user-bind config \[Purpose] Display packet inspection function alarms and alarm threshold related configuration \[View] System view \[Use Cases] \[Command] user-bind rule { A.
IPv6 RA Guard Configuration
\[Command] show raguard policy \[Purpose] View the configuration of the RA Guard policy \[View] System view \[Use Cases] \[Command] show raguard role \[Purpose] View RA Guard interface role configuration \[View] System view \[Use Cases] \[Command] raguard role {user|router|hybrid} no raguard role {user|router|hybrid} \[Purpose] Configure the interface role for the RA Guard function \[Parameter] \[View] Interface view \[Use Cases] \[Command] raguard policy src-ip A B no raguard policy param src-ip no raguard policy \[Purpose] Configure the matching rules for the source IPv6 address of RA packets \[Parameter] \[View] VLAN view \[Use Cases] \[Command] raguard policy src-mac HH\ HH\ HH\ HH\ HH \ HH no raguard policy param src-mac no raguard policy \[Purpose] Configure the matching rules for the source MAC address of RA packets \[Parameter] \[View] VLAN view \[Use Cases] \[Command] raguard policy {hop-limit-high|hop-limit-low} value no raguard policy param {hop-limit-high|hop-limit-low} no raguard policy \[Purpose] Configure the maximum and minimum value matching rules for the hop limit in RA packets \[Parameter] \[View] VLAN view \[Use Cases] \[Command] raguard policy managed-flag {on|off} no raguard policy param managed-flag no raguard policy \[Purpose] Configure the matching rules for the M flag bit in RA packets \[View] VLAN view \[Use Cases] \[Command] raguard policy other-flag {on|off} no raguard policy param other-flag no raguard policy \[Purpose] Configure the matching rules for the O flag bit in RA packets \[View] VLAN view \[Use Cases] \[Command] raguard policy prefix A B/M no raguard policy param prefix no raguard policy \[Purpose] Configure the matching rules for the IPv6 prefixes carried by RA packets \[Parameter] \[View] VLAN view \[Use Cases] \[Command] raguard policy router-pref-max {low|medium|high} no raguard policy param router-pref-max no raguard policy \[Purpose] Configure the highest priority matching rule for routing RA packets \[View] VLAN view \[Notes] When an interface configured with this policy receives RA packets, it will check the routing priority carried by the packet, and RA packets with a priority less than or equal to that configured by the rule will be forwarded, otherwise they will be dropped.
IPSG Configuration
\[Command] show ipv4-source-check config \[Purpose] View the IP packet inspection function configuration information \[View] System view \[Use Cases] \[Command] show ipv6-source-check config \[Purpose] View the configuration information of IPv6 packet inspection function \[View] System view \[Use Cases] \[Command] ipv4-source-check enable no ipv4-source-check enable \[Purpose] Enable IPv4 packet inspection function \[View] VLAN view \[Notes] When the IP packet inspection function is enabled, the device will compare the source IP and source MAC of the received IPv4 packet with the information in the snooping table entry and User-bind table entry, if it can hit, it means the user of the IPv4 packet is a legal user and allows the IPv4 packet of this user to pass, otherwise it is considered an illegal user and drops the IP packet. \[Use Cases] \[Command] ipv4-source-check trusted-interface vlan VLAN-ID no ipv4-source-check trusted-interface vlan VLAN-ID \[Purpose] Configuring IPSG trusted ports \[View] Interface view \[Notes] When configured as an IPSG trusted port, IPv4 packets received from this port will not be IPSG checked and will all be allowed to pass.
SAVI Configuration
\[Command] show savi config \[Purpose] View SAVI function configuration information \[View] System view \[Use Cases] \[Command] savi enable no savi enable \[Purpose] Enable the SAVI detection function of the interface \[View] VLAN view \[Notes] After enabling SAVI function, the device will compare the source IP, source MAC, snooping table entry and User-bind table entry of the received ND protocol packets, DHCPv6 protocol packets, and if it can hit, the packets will be passed, otherwise the packets will be dropped. \[Use Cases] \[Command] savi trusted-interface vlan VLAN-ID no savi trusted-interface vlan VLAN-ID \[Purpose] Configuring SAVI trusted ports \[View] VLAN view \[Notes] After configured as a SAVI trusted port, ND protocol packets and DHCPv6 protocol packets received from this port will not be checked by SAVI and will all be allowed to pass.
ARP Detection Configuration
\[Command] show anti-attack-ckeck config \[Purpose] View ARP detection configuration \[View] System view \[Use Cases] \[Command] arp anti-attack-check enable no arp anti-attack-check enable \[Purpose] Enable the ARP detection function of the interface \[View] VLAN view \[Notes] After enabling ARP Snooping detection function, the device will compare the source IP, source MAC, snooping table entry and User-bind table entry of the received ARP packet, if it can hit, the user of the ARP packet is a legitimate user and the ARP packet of this user is allowed to pass, otherwise it is considered an illegal user and the ARP packet is dropped. \[Use Cases] \[Command] arp anti-attack-check trusted-interface vlan VLAN-ID no arp anti-attack-check trusted-interface vlan VLAN-ID \[Purpose] Configuring ARP detection trusted ports \[View] VLAN view \[Notes] After configured as an ARP detection trusted port, ARP packets received from this port will not be checked and all are allowed to pass.