display attack-defense scan attacker ip

Use display attack-defense scan attacker ip to display information about IPv4 scanning attackers.

Syntax

In standalone mode:

display attack-defense scan attacker ip [ [ local ] [ slot slot-number ] ] [ count ]

In IRF mode:

display attack-defense scan attacker ip [ [ local ] [ chassis chassis-number slot slot-number ] ] [ count ]

Views

Any view

Predefined user roles

network-admin

network-operator

mdc-admin

mdc-operator

Parameters

local: Specifies the device.

slot slot-number: Specifies a card by its slot number. This option is available only when you specify the device. If you do not specify a card, this command displays information about IPv4 scanning attackers for all cards. (In standalone mode.)

chassis chassis-number slot slot-number: Specifies a card on an IRF member device. The chassis-number argument represents the member ID of the IRF member device. The slot-number argument represents the slot number of the card. This option is available only when you specify the device. If you do not specify a card, this command displays information about IPv4 scanning attackers for all cards. (In IRF mode.)

count: Displays the number of matching IPv4 scanning attackers.

Usage guidelines

If you do not specify any parameters, this command displays information about all IPv4 scanning attackers.

Examples

# (In standalone mode.) Display information about all IPv4 scanning attackers.

<Sysname> display attack-defense scan attacker ip
Slot 1:
IP address      VPN instance     DS-Lite tunnel peer  Detected on  Duration(min)
192.68.11.2     --               --                   Local        782
Slot 2:
IP address      VPN instance     DS-Lite tunnel peer  Detected on  Duration(min)

# (In standalone mode.) Display the number of IPv4 scanning attackers.

<Sysname> display attack-defense scan attacker ip count
Slot 1:
Totally 1 attackers.
Slot 2:
Totally 0 attackers.

Table 75: Command output

Field

Description

Totally 1 attackers

Total number of IPv4 scanning attackers.

IP address

IPv4 address of the attacker.

VPN instance

MPLS L3VPN instance to which the attacker's IPv4 address belongs. If the IPv4 address is on the public network, this field displays hyphens (--).

DS-Lite tunnel peer

This field is not supported in the current software version.

IPv6 address of the DS-Lite tunnel peer.

If the device is the AFTR of a DS-Lite tunnel, this field displays the IPv6 address of the B4 element from which the packet comes.

In other situations, this field displays hyphens (--).

Detected on

Where the attack is detected: the device (Local).

Duration(min)

The amount of time the attack lasts, in minutes.

Related commands

display attack-defense scan victim ip

scan detect