1-3
Configuring ARP Source Suppression
Follow these steps to configure ARP source suppression:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable ARP source suppression
arp source-suppression
enable
Required
Disabled by default.
Set the maximum number of packets with the
same source IP address but unresolvable
destination IP addresses that the device can
receive in five consecutive seconds
arp source-suppression
limit limit-value
Optional
10 by default.
Enabling ARP Black Hole Routing
Follow these steps to configure ARP black hole routing:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable ARP black hole routing
arp resolving-route enable
Optional
Enabled by default
Displaying and Maintaining ARP Defense Against IP Packet Attacks
To do…
Use the command…
Remarks
Display the ARP source suppression
configuration information
display arp
source-suppression
Available in any view
Configuring ARP Packet Rate Limit
Introduction
This feature allows you to limit the rate of ARP packets to be delivered to the CPU. For example, if an
attacker sends a large number of ARP packets to an ARP detection enabled device, the CPU of the
device may become overloaded because all the ARP packets are redirected to the CPU for checking.
As a result, the device fails to deliver other functions properly or even crashes. To prevent this, you
need to configure ARP packet rate limit.
It is recommended that you enable this feature after the ARP detection, ARP snooping, or MFF feature
is configured, or use this feature to prevent ARP flood attacks.
Configuration Procedure
Follow these steps to configure ARP packet rate limit:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Summary of Contents for S5500-SI Series
Page 161: ...3 10 GigabitEthernet1 0 1 2 MANUAL...
Page 220: ...1 7 Clearing ARP entries from the ARP table may cause communication failures...
Page 331: ...1 7 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete...
Page 493: ...2 8...
Page 1111: ...1 10 Installing patches Installation completed and patches will continue to run after reboot...