Context
The ATIC alarm policy is implemented based on the traffic log statistics about an anti-DDoS device within the interval of 64 seconds. When the statistics on traffic destined to a Zone reaches the Critical level, the corresponding action is triggered. The delay for automatically executing the blackhole policy is 70 seconds.
Procedure
- Configure a RESTful server.
- Configure the notification mode of second-level blackhole event.
- Enable the RESTful API.
- Set the blackhole mode of the Zone.
- Configure the alarm action.
- Choose Defense > Policy Settings > Zone.
- Click
. - In the Alarm Policy dialog box, set parameters in the Critical area, and set the blackhole action. Table 1 lists related parameters.
Table 1 ActionParameter
|
Description
|
Enable LPU blackhole
|
If Enable LPU blackhole is selected in the Critical area and the value of a parameter exceeds the threshold, this function is enabled.
NOTE: - To implement the blackhole function through the third-party non-DamDDoS system, you are advised to enable the blackhole function locally and set the blackhole type to Enable LPU blackhole. Upon receiving heavy traffic, the local cleaning device blocks the traffic at the fastest speed, alleviating the network bandwidth pressure to a certain extent.
|
- Click OK. The message "Succeeded in configuring the alarm severity rule" is displayed.
Copyright © Huawei Technologies Co., Ltd.