
42-1
42
DHCP Packet Rate Limit Configuration
Whe
uring the DHCP packet rate limit function, go to t
sections for information you are
terested in:
tion to DHCP Packet Rate Limit
n
config
hese
in
z
Introduc
ring DHCP Packet Rate Limit
z
Configu
z
Rate Limit Configuration Example
Intro u
To prevent ARP attacks and attacks from unauthorized DHCP servers, ARP packets and DHCP
ackets will be processed by the switch CPU for validity checking. But, if attackers generate a large
number of ARP packets or DHCP packets, the switch CPU will be under extremely heavy load. As a
even goes down.
packet rate limit on a port and shut down the
port under attack to prevent hazardous impact on the device CPU. For details about ARP packet rate
limit, refer to
on
in this ma
cribes only the D
t rate limit
f
After DHCP packet rate limit is enabl
rt, the sw
er of DHCP
p
e
CP pack
ceeds
the specified value, packets are passing the port at an over-high rate,
s an attack to the port.
In this case, the swit
ts down this p
ceive a
thus protect the switch
f
In addition, the switch supports port state auto-recovery. After a port i
ver-high
acket rate, it resumes automatically after a configurable period of time.
d ction to DHCP Packet Rate Limit
p
result, the switch cannot work normally and
S4500 series Ethernet switches support ARP and DHCP
ARP Operati
nual. The following des
HCP packe
unction.
ed on an Ethernet po
cond. If the number of DH
itch counts the numb
ackets received on this port per s
ets received per second ex
which implie
ch shu
rom attacks.
ort so that it cannot re
ny packet,
s shut down due to o
p
When both port state auto-recovery interval for over-high ARP packet rate and port state auto-recovery
interval for over-high DHCP packet rate are configured on a port, the shorter one will be the
auto-recovery time.
Con
Configuring DHCP Packet Rate Limit
Follow these steps to configure rate limit of DHCP packets:
figuring DHCP Packet Rate Limit
To do…
Use the command…
Remarks
Enter system view
system-view
—