267
To do…
Use the command…
Remarks
Set the maximum number of packets with the
same source IP address but unresolvable
destination IP addresses that the switch can
receive in five consecutive seconds
arp source-suppression limit
limit-value
Optional
10 by default.
Enabling ARP black hole routing
Follow these steps to configure ARP black hole routing:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable ARP black hole routing
arp resolving-route enable
Optional
Enabled by default.
Displaying and maintaining ARP defense against IP packet
attacks
To do…
Use the command…
Remarks
Display the ARP source suppression
configuration information
display arp source-suppression
[
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Configuring ARP packet rate limit
Introduction
This feature allows you to limit the rate of ARP packets to be delivered to the CPU. For example, if an
attacker sends a large number of ARP packets to an ARP detection enabled switch, the CPU of the switch
may become overloaded because all of the ARP packets are redirected to the CPU for checking. As a
result, the switch fails to deliver other functions properly or even crashes. To prevent this, configure ARP
packet rate limit.
Enable this feature after the ARP detection is configured or use this feature to prevent ARP flood attacks.
Configuring ARP packet rate limit
When the ARP packet rate exceeds the rate limit set on an interface, the switch with ARP packet rate limit
enabled sends trap and log messages to inform the event. To avoid too many trap and log messages, you
can set the interval for sending such messages. Within each interval, the switch will output the peak ARP
packet rate in the trap and log messages.
Trap and log messages are generated only after the trap function of ARP packet rate limit is enabled.
Trap and log messages will be sent to the information center of the switch. You can set the parameters of
the information center to determine the output rules of trap and log messages. The output rules specify
whether the messages are allowed to be output and where they are bound for. For the parameter