![FoxGate S6124 Command Manual Download Page 189](http://html1.mh-extra.com/html/foxgate/s6124/s6124_command-manual_2325479189.webp)
189
Example:
Set the threshold of port-based ARP scanning prevention as 10 packets
/second.
Switch(config)#anti-arpscan port-based threshold 10
16.3 anti-arpscan ip-based threshold
Command: anti-arpscan ip-based threshold
<threshold-value>
no anti-arpscan ip-based threshold
Function:
Set the threshold of received messages of the IP-based ARP scanning
prevention. If the rate of received ARP messages exceeds the threshold, the IP messages
from this IP will be blocked. The unit is packet/second. The ―no anti-arpscan ip-based
threshold‖ command will reset the default value, 3 packets/second.
Parameters:
rate threshold, ranging from 1 to 200.
Default Settings:
3 packets/second.
Command Mode:
Global configuration mode
User Guide:
The threshold of port-based ARP scanning prevention should be larger than
the threshold of IP-based ARP scanning prevention, or, the IP-based ARP scanning
prevention will fail.
Example:
Set the threshold of IP-based ARP scanning prevention as 6 packets/second.
Switch(config)#anti-arpscan ip-based threshold 6
16.4 anti-arpscan trust
Command: anti-arpscan trust [port | supertrust-port]
no anti-arpscan trust [port | supertrust-port]
Function:
Configure a port as a trusted port or a supe
r trusted port;‖
no anti-arpscan
trust <port | supertrust-port>
‖command will reset the port as an untrusted port.
Parameters:
None.
Default Settings:
By default all the ports are non- trustful.
Command Mode:
Port configuration mode
User Guide:
If a port is configured as a trusted port, then the ARP scanning prevention
function will not deal with this port, even if the rate of received ARP messages exceeds
the set threshold, this port will not be closed, but the non- trustful IP of this port will still be
checked. If a port is set as a super non- trustful port, then neither the port nor the IP of the
port will be dealt with. If the port is already closed by ARP scanning prevention, it will be
opened right after being set as a trusted port.
When remotely managing a switch with a method like telnet, users should set the uplink
Summary of Contents for S6124
Page 311: ...311 Machine...
Page 314: ...314...