
Networking Requirements
As shown in
, the Router is connected to a server through Ethernet0/0/3 that is added
to VLAN 30 and is connected to users in VLAN 10 and VLAN 20 through Ethernet0/0/1 and
Ethernet0/0/2. The following ARP attacks occur on the network:
l
The server may send several packets with an unreachable destination IP address, and the
number of these packets is larger than the number of packets from common users.
l
After virus attacks occur on user 1, a large number of ARP packets are sent. Among these
packets, the source IP address of certain ARP packets changes on the local network segment
and the source IP address of certain ARP packets is the same as the IP address of the
gateway.
l
User 3 constructs a large number of ARP packets with a fixed IP address to attack the
network.
l
User 4 constructs a large number of ARP packets with an unreachable destination IP address
to attack the network.
ARP security functions are required to be configured on the Router to prevent the preceding
attacks. The rate limit of ARP Miss packets on the server should be greater than the rate limit
of other users.
Figure 6-1
Network diagram for configuring ARP security functions
Router
Server
Ethernet0/0/2
Ethernet0/0/1
User1
User2
VLAN10
User3
User4
VLAN20
Ethernet0/0/3
Configuration Roadmap
The configuration roadmap is as follows:
1.
Enable strict ARP learning.
2.
Enable interface-based ARP entry limiting.
3.
Enable the ARP anti-spoofing function.
4.
Enable the ARP anti-attack function for preventing attacks by sending ARP packets with
a bogus gateway address.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
6 ARP Security Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
145