2-4
A protected MAC address is no longer excluded from detection after the specified aging time expires.
Configuring ARP Packet Source MAC Address Consistency Check
Introduction to ARP Packet Source MAC Address Consistency Check
This feature enables a gateway device to filter out ARP packets with the source MAC address in the
Ethernet header different from the sender MAC address in the ARP message, so that the gateway
device can learn correct ARP entries.
Configuring ARP Packet Source MAC Address Consistency Check
Follow these steps to enable ARP packet source MAC address consistency check:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable ARP packet source MAC
address consistency check
arp anti-attack valid-check
enable
Required
Disabled by default.
Configuring ARP Packet Rate Limit
Introduction to ARP Packet Rate Limit
This feature allows you to limit the rate of ARP packets to be delivered to the CPU. For example, if an
attacker sends a large number of ARP packets to an ARP detection enabled device, the CPU of the
device may become overloaded because all the ARP packets are redirected to the CPU for checking.
As a result, the device cannot deliver other functions properly or even crashes. To prevent it, you need
to enable ARP packet rate limit.
You can enable this feature after ARP detection is configured, or to prevent ARP flood attacks.
Configuring the ARP Packet Rate Limit Function
Follow these steps to configure ARP packet rate limit in Ethernet interface view:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter Ethernet interface view
interface interface-type interface-number
—
Configure ARP packet rate limit
arp rate-limit
{
disable | rate pps drop
}
Required
Disabled by default.
Содержание S5810 Series
Страница 307: ...ii Configured Multicast Group Policy Fails to Take Effect 1 32...
Страница 648: ...1 8 Return to the upper directory Sysname cd Display the current working directory Sysname pwd flash...
Страница 812: ...1 7 Role Slave Sysname stack_3 DeviceD Device type S5810 50S MAC address 000f e200 1003...