4-5
Default Level
2: System level
Parameters
filter
: Specifies the
filter
mode.
monitor
: Specifies the
monitor
mode.
Description
Use the
arp anti-attack source-mac
command to enable source MAC address based ARP attack
detection and specify the detection mode.
Use the
undo arp anti-attack source-mac
command to restore the default.
By default, source MAC address based ARP attack detection is disabled.
After you enable this feature, the device checks the source MAC address of ARP packets received
from the VLAN. If the number of ARP packets received from a source MAC address within five
seconds exceeds the specified threshold:
z
In filter detection mode, the device displays an alarm and filters out the ARP packets from the
MAC address.
z
In monitor detection mode, the device only displays an alarm.
Note that: If no detection mode is specified in the
undo arp anti-attack source-mac
command, both
detection modes are disabled.
Examples
# Enable filter-mode source MAC address based ARP attack detection
<Sysname> system-view
[Sysname] arp anti-attack source-mac filter
arp anti-attack source-mac aging-time
Syntax
arp anti-attack source-mac aging-time time
undo arp anti-attack source-mac aging-time
View
System view
Default Level
2: System level
Parameters
time
: Aging timer for protected MAC addresses, in the range of 60 to 6000 seconds.
Description
Use the
arp anti-attack source-mac aging-time
command to configure the aging timer for protected
MAC addresses.
Use the
undo arp anti-attack source-mac aging-time
command to restore the default.
Содержание E4510-48G
Страница 109: ...2 18 Sysname interface bridge aggregation 1 Sysname Bridge Aggregation1 shutdown ...
Страница 309: ...6 4 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address dhcp alloc ...
Страница 324: ...8 3 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address bootp alloc ...
Страница 530: ...2 5 Sysname mvlan 100 subvlan 10 to 15 ...
Страница 739: ...8 15 Sysname system view Sysname port security trap addresslearned ...
Страница 819: ...13 11 Sysname system view Sysname public key peer key2 import sshkey key pub ...
Страница 857: ...iii 7 Track Configuration Commands 7 1 Track Configuration Commands 7 1 display track 7 1 track nqa 7 2 ...
Страница 914: ...5 17 Sysname reset oam ...
Страница 1064: ...5 30 Slot 2 Set next configuration file successfully ...
Страница 1325: ...21 13 Examples Redirect to member 2 Sysname irf switch to 2 Sysname Slave 2 ...