Suppressing Transmission Rate Of Arp Packets; Establishing The Configuration Task - Huawei Quidway S9300 Configuration Manual

Terabit routing switch
Table of Contents

Advertisement

Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
<Quidway> display arp anti-attack check user-bind interface GigabitEthernet 1/0/0
arp anti-attack check user-bind enable
arp anti-attack check user-bind alarm enable
arp anti-attack check user-bind alarm threshold 50
ARP packet drop count = 10

4.5 Suppressing Transmission Rate of ARP Packets

This section describes how to suppress the transmission rate of the ARP packets.

4.5.1 Establishing the Configuration Task

4.5.2 Configuring Source-based ARP Suppression
4.5.3 Configuring Source-based ARP Miss Suppression
4.5.4 Setting the Suppression Time of ARP Miss Messages
4.5.5 Suppressing Transmission Rate of ARP Packets
4.5.6 Checking the Configuration
4.5.1 Establishing the Configuration Task
Applicable Environment
On an Ethernet Metropolitan Area Network (MAN), ARP entries are easily attacked; therefore,
it is required to configure ARP suppression features on the access layer or convergence layer to
ensure network security.
l
l
l
Pre-configuration Tasks
Before configuring ARP suppression, complete the following task:
l
Data Preparation
To configure ARP suppression, you need the following data.
Issue 06 (2010–01–08)
To prevent excessive ARP packets from increasing the CPU workload and occupying
excessive ARP entries, you can suppress the transmission rate of ARP packets. Then the
transmission rate of the ARP packets transmitted to the main control board is limited.
To prevent a host from sending excessive IP packets whose destination IP addresses cannot
be resolved, you can suppress the source IP address that sends the packets, that is, configure
the suppression on ARP Miss source. Then these IP packets are discarded.
After the IP source guard function is enabled on an interface, all the ARP packets passing
through the interface are forwarded to the security module for check. If excessive ARP
packets are sent to the security module, the security module will be impacted. In this case,
you can suppress the transmission rate of the ARP packets; the packets that exceed the
transmission rate are discarded.
Setting the parameters of the link layer protocol and the IP address of the interface and
enabling the link-layer protocol
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
4 ARP Security Configuration
4-15

Advertisement

Table of Contents
loading

Table of Contents