Operation Manual – ARP
H3C S3610&S5510 Series Ethernet Switches
Chapter 1 ARP Configuration
1-7
z
Informing other devices of its MAC address change so that they can update their
ARP entries.
A device receiving a gratuitous ARP packet can add the information carried in the
packet to its own dynamic ARP mapping table if it finds no corresponding ARP entry for
the ARP packet in the cache.
1.3.2 Configuring Gratuitous ARP
Follow these steps to configure gratuitous ARP:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable the device to send
gratuitous ARP packets
when receiving ARP
requests from another
network segment
gratuitous-arp-sending
enable
Required
By default, an switch
cannot send gratuitous
ARP packets when
receiving ARP requests
from another network
segment.
Enable the gratuitous
ARP packet learning
function
gratuitous-arp-learning
enable
Required
Disabled by default.
1.4 Configuring ARP Source Suppression
1.4.1 Introduction to ARP Source Suppression
If a host attacks the device on a network by sending large amounts of IP packets whose
IP addresses cannot be resolved:
z
The device sends large amounts of ARP request messages to the destination
subnet, which increases the load of the destination subnet.
z
The device continuously resolves destination IP addresses, which increase the
load of the CPU.
To protect the device against this kind of attack, you can enable the ARP source
suppression function. With the function enabled, whenever the number of packets with
unresolvable IP addresses that a host on the network sends to the device within five
seconds exceeds the specified threshold, the device drops all subsequent packets with
the same source IP address in another five coming seconds. This helps in protecting
the device against the attack.
1.4.2 Configuring ARP Source Suppression
Follow these steps to configure ARP source suppression: