
ARP speed-limit for source-MAC configuration:
MAC-address suppress-rate(pps)(rate=0 means function disabled)
-------------------------------------------------------------------------------
All 0
-------------------------------------------------------------------------------
0 specified MAC addresses are configured, spec is 256 items.
ARP speed-limit for source-IP configuration:
IP-address suppress-rate(pps)(rate=0 means function disabled)
------------------------------------------------------------------------
2.2.4.2 10
Others 15
------------------------------------------------------------------------
1 specified IP addresses are configured, spec is 128 items.
ARP miss speed-limit for source-IP configuration:
IP-address suppress-rate(pps)(rate=0 means function disabled)
------------------------------------------------------------------------
2.2.2.2 50
Others 20
------------------------------------------------------------------------
1 specified IP addresses are configured, spec is 128 items.
You can use the
display arp packet statistics
command to view the number of discarded ARP
packets and the number of learned ARP entries.
<Router>
display arp packet statistics
ARP Pkt Received: sum 167
ARP Learnt Count: sum 8
ARP Pkt Discard For Limit: sum 5
ARP Pkt Discard For SpeedLimit: sum 0
ARP Pkt Discard For Proxy Suppress: sum 0
ARP Pkt Discard For Other: sum 3
In addition, you can also use the
display arp anti-attack gateway-duplicate item
command to
view information about attacks from packets with a forged gateway address on the current
network.
<Router>
display arp anti-attack gateway-duplicate item
interface IP address MAC address VLANID aging time
-------------------------------------------------------------------------------
Ethernet0/0/1 2.2.1.10 0000-0000-0002 10 153
Ethernet0/0/2 2.2.4.10 0000-0000-0004 20 179
-------------------------------------------------------------------------------
There are 2 records in gateway conflict table
----End
Configuration Files
#
sysname Router
#
vlan batch 10 20 30
#
arp speed-limit source-ip maximum 15
arp-miss speed-limit source-ip maximum 20
arp learning strict
#
arp anti-attack entry-check fixed-mac enable
arp anti-attack gateway-duplicate enable
arp-miss speed-limit source-ip 2.2.2.2 maximum 50
arp speed-limit source-ip 2.2.4.2 maximum 10
#
interface Ethernet0/0/1
port hybrid pvid vlan 10
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
6 ARP Security Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
148