anti-ddos loop-check

Function

Using the anti-ddos loop-check command, you can configure the loop check function.

Using the undo anti-ddos loop-check command, you can disable the loop check function.

Format

anti-ddos loop-check [ match-time match-times ]

undo anti-ddos loop-check

Parameters

Parameter Description Value
match-times Specifies match times for loop packets. The value is an integer ranging from 1 to 20. The default value is 4.

Views

System view

Default Level

2: Configuration level

Usage Guidelines

This command is used to configure the loop check function. After the command is configured, the system automatically checks whether received packets are repetitive. If yes, the loop occurs. After loop counts reaches a value, the system automatically cancels the traffic-diversion route to the destination IP address. By default, the function is disabled.

Parameter match-time specifies match times for loop packets. When the match times exceeds the match-time value, the system cancels the traffic-diversion route. The default match times is 4, that is, the system cancels the traffic-diversion route when loop packets match for the fifth times.

Before configuring the loop check function, please add the destination IP address of traffic-diversion to the Zone.

NOTICE:

If a traffic diversion route loop occurs after this function is enabled, the system will automatically cancel the traffic diversion route.

Example

# Configure the loop check function and set the match times for loop packets to 5.

<sysname> system-view
[sysname] anti-ddos loop-check match-time 5

Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.