Configuring Arp Anti-Attack; Establishing The Configuration Task - Huawei Quidway S9300 Configuration Manual

Terabit routing switch
Table of Contents

Advertisement

4 ARP Security Configuration
Vlanif100
Vlanif200
------------------------------------------------------------
Total:2
force-enable:1
force-disable:1
Run the display arp-limit [ interface interface-type interface-number ] [ vlan vlan-id ]
command, and you can view the maximum number of ARP entries that can be learned by an
interface or a VLAN.
<Quidway> display arp-limit interface GigabitEthernet 1/0/10
interface
---------------------------------------------------------------------------
GigabitEthernet1/0/10
GigabitEthernet1/0/10
GigabitEthernet1/0/10
GigabitEthernet1/0/10
GigabitEthernet1/0/10
GigabitEthernet1/0/10
GigabitEthernet1/0/10
GigabitEthernet1/0/10
---------------------------------------------------------------------------
Total:8
<Quidway> display arp-limit vlan 3
interface
---------------------------------------------------------------------------
GigabitEthernet1/0/10
---------------------------------------------------------------------------
Total:1

4.4 Configuring ARP Anti-Attack

This section describes how to configure the ARP anti-attack function.

4.4.1 Establishing the Configuration Task

4.4.2 Preventing the ARP Address Spoofing Attack
4.4.3 Preventing the ARP Gateway Duplicate Attack
4.4.4 Preventing the Man-in-the-Middle Attack
4.4.5 Configuring ARP Proxy on a VPLS Network
4.4.6 Configuring DHCP to Trigger ARP Learning
4.4.7 (Optional) Configuring the S9300 to Discard Gratuitous ARP Packets
4.4.8 Enabling Log and Alarm Functions for Potential Attacks
4.4.9 Checking the Configuration
4.4.1 Establishing the Configuration Task
Applicable Environment
On an Ethernet Metropolitan Area Network (MAN), ARP entries are easily attacked; therefore,
it is required to configure the ARP anti-attack function on the access layer or convergence layer
to ensure network security.
4-8
LimitNum
1000
1000
1000
1000
1000
1000
1000
1000
LimitNum
1000
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
force-disable
force-enable
VlanID
LearnedNum(Mainboard)
3
0
4
0
5
0
6
0
7
0
8
0
9
0
10
0
VlanID
LearnedNum(Mainboard)
3
0
Issue 06 (2010–01–08)

Advertisement

Table of Contents
loading

Table of Contents