4-4
Follow these steps to configure protected MAC addresses:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Configure protected MAC
addresses
arp anti-attack source-mac
exclude-mac mac-address
&<1-n>
Optional
Not configured by default.
Configuring the aging timer for protected MAC addresses
Follow these steps to configure the aging timer for protected MAC addresses:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Configure aging timer for
protected MAC addresses
arp anti-attack source-mac
aging-time time
Optional
Five minutes by default.
Configuring the threshold
Follow these steps to configure the threshold:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Configure the threshold
arp anti-attack source-mac threshold
threshold-value
Optional
50 by default.
Displaying and Maintaining Source MAC Address Based ARP Attack Detection
To do…
Use the command…
Remarks
Display attacking
entries detected
display arp anti-attack source-mac
{
slot
slot-number | interface
interface-type
interface-number
}
Available in any view
A protected MAC address is no longer excluded from detection after the specified aging time expires.
Configuring ARP Packet Source MAC Address Consistency Check
Introduction
This feature enables a gateway device to filter out ARP packets with the source MAC address in the
Ethernet header different from the sender MAC address in the ARP message, so that the gateway
device can learn correct ARP entries.