Enabling the Second-Level Blackhole

Real-time statistics about traffic destined to a specified IP address is collected for comparison with the threshold every second. When the traffic of a specified IP address exceeds the blackhole threshold, the corresponding blackhole action is triggered.

Procedure

  1. Configure a blackhole API.
  2. Configure the notification mode of second-level blackhole event.
  3. Set the blackhole mode of the Zone.
  4. Enable the second-level blackhole.
    1. Choose Defense > Policy Settings > Zone.
    2. Click of the Zone.
    3. In the Defense Policy dialog box, configure a blackhole policy. Table 1 lists related parameters.
      Table 1 Blackhole parameter configuration

      Parameter

      Description

      Second-Level Blackhole

      Select Enabled.

      Threshold (Mbit/s)

      Set the blackhole threshold.

      When the traffic exceeds the value of Threshold, enable the corresponding blackhole type for defense.

      Type

      Set the blackhole type to Blackhole API.

      NOTE:

      The blackhole API is the DamDDoS API. To implement the blackhole function using the blocking service provided by the DamDDoS, set Type to Blackhole API.

    4. Click OK. When the traffic of a specified IP address exceeds the blackhole threshold, the corresponding blackhole action is triggered.

Copyright © Huawei Technologies Co., Ltd.