151
IP-COM(config-if)# ip arp inspection trust
IP-COM(config-if)# ip arp inspection limit rate 200
Note:
Enable ARP attack defense on port 10 and configure ARP RX rate to 200PPS
IP-COM(config)# interface rang gigabitethernet 0/11-20
IP-COM(config-if)# ip arp inspection trust
IP-COM(config-if)# ip arp inspection limit rate 150
Note:
Enable ARP attack defense on ports 11-20 and configure ARP RX rate to 150PPS
Disable ARP Attack Defense
IP-COM(config)# interface gigabitethernet 0/10
IP-COM(config-if)# no ip arp inspection trust
Note:
Disable ARP Attack Defense on port 10
IP-COM(config)# interface rang gigabitethernet 0/11-20
IP-COM(config-if)# no ip arp inspection trust
Note:
Disable ARP Attack Defense on ports11-20
5.3.29 Config MAC Attack Defense
IP-COM(config)# interface gigabitethernet 0/1
IP-COM(config-if)# mac-address learning-limit 8191
Note:
Set MAC-address learning on port 1 unlimited
IP-COM(config-if)# mac-address learning-limit 0
Note:
Disable MAC-address learning on port 1
IP-COM(config-if)# mac-address learning-limit 200
Note:
Set MAC-address learning Limit on port 1 to 200
IP-COM(config)# interface rang gigabitethernet 0/1-24
IP-COM(config-if)# mac-address learning-limit 2000
Note:
Set MAC-address learning Limit on ports 1-24 to 2000
IP-COM(config-if)# mac-address unknown-discard
Note:
Enable the function to drop the excessive MAC-address learning packets (beyond address limit)
IP-COM(config-if)#no mac-address unknown-discard
Note:
Disable the function to drop the excessive MAC-address learning packets (beyond address limit)
Summary of Contents for G3224P
Page 1: ......