display attack-defense scan victim ip

Use display attack-defense scan victim ip to display information about IPv4 scanning attack victims.

Syntax

In standalone mode:

display attack-defense scan victim ip [ [ local ] [ slot slot-number ] ] [ count ]

In IRF mode:

display attack-defense scan victim ip [ [ local ] [ chassis chassis-number slot slot-number ] ] [ count ]

Views

Any view

Predefined user roles

network-admin

network-operator

mdc-admin

mdc-operator

Parameters

local: Specifies the device.

slot slot-number: Specifies a card by its slot number. This option is available only when you specify the device. If you do not specify a card, this command displays information about IPv4 scanning attack victims for all cards. (In standalone mode.)

chassis chassis-number slot slot-number: Specifies a card on an IRF member device. The chassis-number argument represents the member ID of the IRF member device. The slot-number argument represents the slot number of the card. This option is available only when you specify the device. If you do not specify a card, this command displays information about IPv4 scanning attack victims for all cards. (In IRF mode.)

count: Displays the number of matching IPv4 scanning attack victims.

Usage guidelines

If you do not specify any parameters, this command displays information about all IPv4 scanning attack victims.

Examples

# (In standalone mode.) Display information about all IPv4 scanning attack victims.

<Sysname> display attack-defense scan victim ip
Slot 1:
IP address      VPN instance                    Detected on        Duration(min)
192.168.24.82   --                              Local              782
Slot 2:
IP address      VPN instance                    Detected on        Duration(min)

# (In standalone mode.) Display the number of IPv4 scanning attack victims.

<Sysname> display attack-defense scan victim ip count
Slot 1:
Totally 1 victim IP addresses.
Slot 2:
Totally 0 victim IP addresses.

Table 77: Command output

Field

Description

Totally 1 victim IP addresses

Total number of IPv4 scanning attack victims.

IP address

IPv4 address of the victim.

VPN instance

MPLS L3VPN instance to which the victim IPv4 address belongs. If the victim IPv4 address is on the public network, this field displays hyphens (--).

Detected on

Where the attack is detected: the device (Local).

Duration(min)

The amount of time the attack lasts, in minutes.

Related commands

display attack-defense scan attacker ip

scan detect