266
Task
Remarks
Optional
Configure this function on access
devices (recommended).
Configuring ARP automatic scanning and fixed
ARP
Optional
Configure this function on gateways
(recommended).
Configuring ARP gateway protection
Optional
Configure this function on access
devices (recommended).
Optional
Configure this function on access
devices (recommended).
Configuring ARP defense against IP packet attacks
Introduction
If the switch receives a large number of IP packets from a host addressed to unreachable destinations,
The switch sends a large number of ARP requests to the destination subnets, and thus the load of the
destination subnets increases.
The switch keeps trying to resolve destination IP addresses, which increases the load on the CPU.
To protect the switch from IP packet attacks, you can enable the ARP source suppression function or ARP
black hole routing function.
If the packets have the same source address, you can enable the ARP source suppression function. With
the function enabled, whenever the number of ARP requests triggered by the packets with unresolvable
destination IP addresses from a host within five seconds exceeds a specified threshold, the switch
suppresses the packets of the sending host from triggering any ARP requests within the following five
seconds.
If the packets have various source addresses, you can enable the ARP black hole routing function. After
receiving an IP packet whose destination IP address cannot be resolved by ARP, the switch with this
function enabled immediately creates a black hole route and simply drops all packets matching the route
during the aging time of the black hole route.
Configuring ARP source suppression
Follow
these
steps
to
configure
ARP
source
suppression:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable ARP source suppression
arp source-suppression enable
Required
Disabled by default.