
Run the
display arp anti-attack gateway-duplicate item
command to view information about
bogus gateway address attacks.
<Huawei>
display arp anti-attack gateway-duplicate item
interface IP address MAC address VLANID aging time
-------------------------------------------------------------------------------
GigabitEthernet1/0/0 2.1.1.1 0000-0000-0002 2 150
-------------------------------------------------------------------------------
There are 1 records in gateway conflict table
6.5 Configuring ARP Suppression
If the AR1200-S receives a lot of ARP attack packets, the ARP table overflows or the CPU usage
is high. The AR1200-S prevents ARP attacks by discarding attack packets and limiting the rate
of attack packets.
6.5.1 Establishing the Configuration Task
Before configuring ARP suppression, familiarize yourself with the applicable environment,
complete the pre-configuration tasks, and obtain the data required for the configuration. This
will help you complete the configuration task quickly and accurately.
Applicable Environment
On intranets, ARP entries are often used to initiate attacks; therefore, it is required to configure
ARP anti-attack on the access layer to ensure network security.
l
To prevent excess ARP packets from occupying the CPU and prevent excess ARP entries,
configure the rate limit for ARP packets to limit the number of ARP packets sent to the
SRU.
l
To prevent a host from sending excess IP packets with destination IP addresses that cannot
be resolved, configure the rate limit for ARP Miss packets. The AR1200-S discards these
IP packets.
l
After IP source guard is enabled on an interface, all the ARP packets passing through the
interface are forwarded to the security module for checking. If excess ARP packets are sent
to the security module, performance of the security module deteriorates. To solve this
problem, configure the rate limit for ARP packets so that the packets that exceed the rate
limit are discarded.
Pre-configuration Tasks
Before configuring ARP suppression, complete the following task:
l
Setting link layer protocol parameters and the interface IP address and enabling the link
layer protocol
Data Preparation
To configure ARP suppression, you need the following data.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
6 ARP Security Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
136