Configuring a Blackhole Policy Based on the Alarm Severity

Context

The ATIC alarm policy is implemented based on the traffic log statistics about an anti-DDoS device within the interval of 64 seconds. When the statistics on traffic destined to a Zone reaches the Critical level, the corresponding action is triggered. The delay for automatically executing the blackhole policy is 70 seconds.

Procedure

  1. Configure the notification mode of second-level blackhole event.
  2. Set the blackhole mode of the Zone.
  3. Configure the alarm action.
    1. Choose Defense > Policy Settings > Zone.
    2. Click .
    3. In the Alarm Policy dialog box, set Action to Enable blackhole in the Critical area. Table 1 lists related parameters.
      Table 1 Action

      Parameter

      Description

      Enable LPU blackhole

      If Enable LPU blackhole is selected in the Critical area and the value of a parameter exceeds the threshold, this function is enabled.

    4. Click OK. The message "Succeeded in configuring the alarm severity rule" is displayed.

Copyright © Huawei Technologies Co., Ltd.