1-2
Task
Remarks
Configuring Source MAC Address Based
ARP Attack Detection
Optional
Configure this function on gateways
(recommended).
Configuring ARP Packet Source MAC
Address Consistency Check
Optional
Configure this function on gateways
(recommended).
Configuring ARP Active Acknowledgement
Optional
Configure this function on gateways
(recommended).
Optional
Configure this function on access
devices (recommended).
Configuring ARP Automatic Scanning and
Fixed ARP
Optional
Configure this function on gateways
(recommended).
Configuring ARP Gateway Protection
Optional
Configure this function on access
devices (recommended).
User and
gateway
spoofing
prevention
Optional
Configure this function on access
devices (recommended).
Configuring ARP Defense Against IP Packet Attacks
Introduction
If a device receives large numbers of IP packets from a host to unreachable destinations,
z
The device sends large numbers of ARP requests to the destination subnets, which increases the
load of the destination subnets.
z
The device keeps trying to resolve destination IP addresses, which increases the load of the CPU.
To protect the device from IP packet attacks, you can enable the ARP source suppression function or
ARP black hole routing function.
If the packets have the same source address, you can enable the ARP source suppression function.
With the function enabled, whenever the number of ARP requests triggered by the packets with
unresolvable destination IP addresses from a host within five seconds exceeds a specified threshold,
the device suppresses the sending host from triggering any ARP requests within the following five
seconds.
If the packets have various source addresses, you can enable the ARP black hole routing function.
After receiving an IP packet whose destination IP address cannot be resolved by ARP, the device with
this function enabled immediately creates a black hole route and simply drops all packets matching the
route during the aging time of the black hole route.
Summary of Contents for S5500-SI Series
Page 161: ...3 10 GigabitEthernet1 0 1 2 MANUAL...
Page 220: ...1 7 Clearing ARP entries from the ARP table may cause communication failures...
Page 331: ...1 7 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete...
Page 493: ...2 8...
Page 1111: ...1 10 Installing patches Installation completed and patches will continue to run after reboot...