Configuration Guide
NFPP Configuration
rate-limit threshold. When the ARP packet rate exceeds the warning threshold,
it will prompt the warning messages and send the TRAP message. The
host-based attack detection can isolate the attack source.
Besides, ARP-guard is able to detect the ARP scan. ARP scan is that the
source MAC address on link layer is fixed while the source IP address is
changing, or the source MAC address and source IP address are fixed while the
destination IP address is changing. Ruijie products only support to detect the
first ARP scan (the source MAC address on link layer is fixed while the source
IP address is changing).
It is worth mentioning that ARP-guard is only for the ARP DoS attack, rather
than ARP fraud or dealing with the ARP attack problems in the network.
ARP-guard configuration commands include:
Enabling arp-guard
Configuring the isolated time
Configuring the monitored time
Configuring the monitored host limit
Host-based rate-limit and attack detection
Port-based rate-limit and attack detection
Clearing the monitored hosts
Clearing the ARP scanning list
Showing related arp-guard information
Enabling ARP-guard
You can enable arp-guard in the nfpp configuration mode or in the interface
configuration mode. By default, the arp-guard is enabled.
Command
Function
Ruijie#
configure terminal
Enter the global configuration mode.
Ruijie(config)#
nfpp
Enter the nfpp configuration mode.
Ruijie(config-nfpp)#
arp-guard enable
Enable the arp-guard. By default,
arp-guard is enabled.
Ruijie(config-nfpp)#
end
Return to the privileged EXEC mode.
Ruijie#
configure terminal
Enter the global configuration mode.
Ruijie#
interface
interface-name
Enter the interface configuration mode.
Содержание RG-S2900G-E Series
Страница 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Страница 91: ...Configuration Guide Configuring PoE Configuration ...
Страница 133: ...Configuration Guide EEE Configuration ...
Страница 319: ...Configuration Guide QinQ Configuration ...
Страница 408: ......
Страница 409: ...IP Routing Configuration 1 Static Route Configuration ...
Страница 412: ......
Страница 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Страница 621: ...Configuration Guide CPU Protection Configuration udp helper 180 4 dhcp client 180 4 lacp 180 4 ...
Страница 757: ......
Страница 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Страница 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Страница 901: ...Configuration Guide ERSPAN Configuration ...
Страница 902: ...Web based Configuration 1 Web based Configuration ...