
statistics on the ARP Miss packets. If a source IP address triggers the ARP Miss packets
continuously in a period and the triggering rate exceeds the threshold, the AR1200-S considers
that an attack occurs.
When the AR1200-S detects an attack, configure the rate limit for ARP Miss packets to limit
the rate of ARP Miss packets so that the CPU is protected and other services can be processed
by the CPU.
Rate Limiting on ARP Packets and ARP Miss Packets
The AR1200-S limits the rate of sending ARP packets globally, based on the interface, or based
on the VLAN ID and the rate of sending ARP Miss packets globally. This prevents a large
number of ARP packets or ARP Miss packets from being sent to the security module. System
performance does not deteriorate.
6.3 Configuring ARP Entry Limiting
This section describes how to configure ARP Entry Limiting.
6.3.1 Establishing the Configuration Task
Before configuring ARP entry limiting, familiarize yourself with the applicable environment,
complete the pre-configuration tasks, and obtain the data required for the configuration. This
will help you complete the configuration task quickly and accurately.
Applicable Environment
After strict ARP learning is enabled, the AR1200-S learns only the ARP Reply packets
corresponding to the ARP Request packets that it sends.
You can configure interface-based ARP entry limiting to limit the number of ARP entries
dynamically learned by the interfaces.
Pre-configuration Tasks
Before configuring ARP entry limiting, complete the following task:
l
Setting link layer protocol parameters and the interface IP address so that the link layer
protocol is Up
Data Preparation
To configure ARP entry limiting, you need the following data.
No.
Data
1
Type and number of the interface where ARP
entry limiting will be configured
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
6 ARP Security Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
128