DES-7200 Configuration Guide Chapter 12 NFPP Configuration
12-21
Command Function
DES-7200# show nfpp ip-guard summary
Show the configurations.
DES-7200# copy running-config
startup-config
Save the configurations.
Caution
With the ip-guard disabled, the monitored hosts are auto-cleared.
12.4.3 Configuring the
isolated time
For the isolated time of the attacker, it can be configured in the global or interface configuration
mode. By default, the isolated time is configured in the global configuration mode.
Command Function
DES-7200# configure terminal
Enter the global configuration mode.
DES-7200(config)# nfpp
Enter the nfpp configuration mode.
DES-7200(config-nfpp)# ip-guard
isolate-period [seconds | permanent]
Configure the global isolated time, ranging 0s,
30-86400s(one day). The default value is 0s,
representing no isolation. Permanent represents
permanent isolation.
DES-7200(config-nfpp)# end
Return to the privileged EXEC mode.
DES-7200# configure terminal
Enter the global configuration mode.
DES-7200(config)# interface
interface-name
Enter the interface configuration mode.
DES-7200(config-if)# nfpp arp-guard
isolate-period [seconds | permanent]
Configure the isolated time on the port, ranging 0s,
180-86400s(one day). By default, the isolated time is
configured globally. 0s represents no isolation.
Permanent represents permanent isolation.
DES-7200(config-if)# end
Return to the privileged EXEC mode.
DES-7200# show nfpp ip-guard summary
Show the parameter settings.
DES-7200# copy running-config
startup-config
Save the configurations.
To restore the global isolated time to the default value, use the no ip-guard isolate-period
command in the nfpp configuration mode. If the isolated time has been configured on a port,
you can use the no ip-guard isolate-period command to remove the port-based isolated time