Configuring the IP blacklist feature

The IP blacklist feature filters packets sourced from IP addresses in blacklist entries.

IP blacklist entries can be manually added or dynamically learned:

To configure the IP blacklist feature:

Step

Command

Remarks

1. Enter system view.

system-view

N/A

2. (Optional.) Enable the global blacklist feature.

blacklist global enable

By default, the global blacklist feature is disabled.

If the global blacklist feature is enabled, the blacklist feature is enabled on all interfaces.

3. (Optional.) Add an IPv4 blacklist entry.

blacklist ip source-ip-address [ vpn-instance vpn-instance-name ] [ timeout minutes ]

By default, no IPv4 blacklist entries exist.

4. (Optional.) Add an IPv6 blacklist entry.

blacklist ipv6 source-ipv6-address [ vpn-instance vpn-instance-name ] [ timeout minutes ]

By default, no IPv6 blacklist entries exist.

5. (Optional.) Enable logging for the blacklist feature.

blacklist logging enable

By default, logging is disabled for the blacklist feature.