
6.4.6 Checking the Configuration
This section describes how to check the ARP anti-attack configuration.
Procedure
l
Run the
display arp anti-attack configuration
{
arp-rate-limit
|
arpmiss-rate-limit
|
arp-speed-limit
|
arpmiss-speed-limit
|
entry-check
|
gateway-duplicate
|
log-trap-
timer
|
all
} command to check the ARP anti-attack configuration.
l
Run the
display arp anti-attack gateway-duplicate item
command to check information
about bogus gateway address attacks.
----End
Example
Run the
display arp anti-attack configuration
all
command to view the ARP anti-attack
configuration.
<Huawei>
display arp anti-attack configuration all
ARP anti-attack packet-check function: enable
ARP anti-attack entry-check mode: disabled
ARP gateway-duplicate anti-attack function: disabled
ARP rate-limit configuration:
-------------------------------------------------------------------------------
Global configuration:
arp anti-attack rate-limit enable
arp packet drop count = 0
Interface configuration:
-------------------------------------------------------------------------------
ARP miss rate-limit configuration:
-------------------------------------------------------------------------------
Global configuration:
arp-miss anti-attack rate-limit enable
-------------------------------------------------------------------------------
ARP speed-limit for source-MAC configuration:
MAC-address suppress-rate(pps)(rate=0 means function disabled)
-------------------------------------------------------------------------------
0000-0000-0001 200
Others 100
-------------------------------------------------------------------------------
1 specified MAC addresses are configured, spec is 256 items.
ARP speed-limit for source-IP configuration:
IP-address suppress-rate(pps)(rate=0 means function disabled)
-------------------------------------------------------------------------------
10.0.0.1 512
Others 126
-------------------------------------------------------------------------------
1 specified IP addresses are configured, spec is 128 items.
ARP miss speed-limit for source-IP configuration:
IP-address suppress-rate(pps)(rate=0 means function disabled)
-------------------------------------------------------------------------------
10.134.23.6 400
Others 500
-------------------------------------------------------------------------------
1 specified IP addresses are configured, spec is 128 items.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
6 ARP Security Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
135