H3C Low-End Ethernet Switches Configuration Examples
ARP Attack Prevention
Chapter 1 ARP Attack Prevention Overview
1-8
Task
To do…
Use the command…
Remarks
Enter Ethernet port
view
interface interface-type
interface-number
—
Enable ARP
packet rate limit
arp rate-limit enable
Required
Disabled by
default.
Configure the
maximum ARP
packet rate
allowed on the port
arp rate-limit rate
Optional
By default, the
maximum ARP
packet rate allowed
on a port is 15 pps.
Return to system
view
quit
—
Enable the port
state
auto-recovery
function
arp protective-down
recover enable
Optional
Disabled by
default.
Configure
ARP
packet rate
limit
Configure the port
state
auto-recovery
interval
arp protective-down
recover interval interval
Optional
By default, when
the port state
auto-recovery
function is enabled,
the port state
auto-recovery
interval is 300
seconds.
Note:
For detailed information about ARP attack prevention supported by a switch model,
refer to its operation and command manuals.
1.4 Device Models that Supports ARP Attack Prevention
Table 1-3
Device models that supports ARP attack prevention
Feature
Device model
DHCP
snooping
ARP attack
detection
IP static
binding
ARP packet
rate limit
S5600 (Release 1602)
z
z
z
z
S5100-EI (Release 2200)
z
z
z
z
S5100-SI (Release 2200)
z
z
z
z
S3600-EI (Release 1602)
z
z
z
z