
1-2
Task
Remarks
Configuring ARP Packet Source MAC
Optional
Configure this function on gateways
(recommended).
Configuring ARP Active Acknowledgement
Optional
Configure this function on gateways
(recommended).
User and
gateway
spoofing
prevention
Optional
Configure this function on access
devices (recommended).
Configuring ARP Defense Against IP Packet Attacks
Introduction
If a device receives large numbers of IP packets from a host to unreachable destinations,
z
The device sends large numbers of ARP requests to the destination subnets, which increases the
load of the destination subnets.
z
The device keeps trying to resolve destination IP addresses, which increases the load of the CPU.
To protect the device from IP packet attacks, you can enable the ARP source suppression function or
ARP black hole routing function.
If the packets have the same source address, you can enable the ARP source suppression function.
With the function enabled, whenever the number of ARP requests triggered by the packets with
unresolvable destination IP addresses from a host within five seconds exceeds a specified threshold,
the device suppresses the sending host from triggering any ARP requests within the following five
seconds.
If the packets have various source addresses, you can enable the ARP black hole routing function. After
receiving an IP packet whose destination IP address cannot be resolved by ARP, the device with this
function enabled immediately creates a black hole route and simply drops all packets matching the
route during the aging time of the black hole route.
Configuring ARP Source Suppression
Follow these steps to configure ARP source suppression:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable ARP source suppression
arp source-suppression enable
Required
Disabled by default.
Set the maximum number of packets
with the same source IP address but
unresolvable destination IP
addresses that the device can
receive in five consecutive seconds
arp source-suppression limit
limit-value
Optional
10 by default.
Содержание S5120-EI Series
Страница 139: ...ii...
Страница 268: ...3 3 SwitchB system view SwitchB interface vlan interface 1 SwitchB Vlan interface1 ip address dhcp alloc...
Страница 328: ...i Table of Contents 1 Dual Stack Configuration 1 1 Dual Stack Overview 1 1 Configuring Dual Stack 1 1...
Страница 578: ...1 21 C...
Страница 739: ...1 12 Enable ARP detection based on 802 1X security entries SwitchB arp detection mode dot1x...
Страница 926: ...2 8...
Страница 942: ...ii Single Device Upgrade 3 4 IRF System Upgrade 3 5...
Страница 985: ...1 1...
Страница 1018: ...1 6...