
6.5.5 Configuring Rate Limiting of ARP Miss Packets
This section describes how to configure rate limiting for ARP Miss packets.
Context
If many ARP Miss packets are triggered, the system is busy in broadcasting ARP request packets
and its performance deteriorates. After ARP Miss suppression is configured, the system counts
ARP Miss packets generated within a specified period and discards excess ARP Miss packets.
Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
Run:
arp-miss anti-attack rate-limit enable
Rate limiting of ARP Miss packets is enabled globally.
By default, rate limiting of ARP Miss packets is disabled globally.
Step 3
Run:
arp-miss anti-attack rate-limit
packet-number
[
interval-value
]
The rate limit duration and the rate limit of ARP Miss packets are set.
After the rate limit duration and the rate limit of ARP Miss packets are set, ARP Miss packets
that exceed the rate limit in the rate limit duration are discarded. By default, the rate limit of
ARP Miss packets is 100 packets per second.
Step 4
(Optional) Run:
arp-miss anti-attack rate-limit alarm enable
The alarm function for the discarded ARP Miss packets that exceed the rate limit is enabled.
By default, the alarm function is disabled.
Step 5
(Optional) Run:
arp-miss anti-attack rate-limit alarm threshold
threshold
The alarm threshold for the discarded ARP Miss packets that exceed the rate limit is set.
By default, the alarm threshold is 100.
----End
6.5.6 Configuring Source MAC Address-based ARP Packet
Suppression
This section describes how to configure source MAC address-based ARP packet suppression.
Procedure
Step 1
Run:
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
6 ARP Security Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
140