HP 3600 v2 Series Configuration Manual page 388

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

Figure 116 Network diagram
Host A
Configuration considerations
If the attacking packets have the same source address, you can enable the ARP source suppression
function with the following steps:
1.
Enable ARP source suppression.
2.
Set the threshold for ARP packets from the same source address to 100. If the number of ARP
requests sourced from the same IP address in 5 seconds exceeds 100, the device suppresses the
IP packets sourced from this IP address from triggering any ARP requests within the following 5
seconds.
If the attacking packets have different source addresses, enable the ARP black hole routing function on
the device.
Configuration procedure
1.
Enable ARP source suppression on the device and set the threshold for ARP packets from the same
source address to 100.
<Device> system-view
[Device] arp source-suppression enable
[Device] arp source-suppression limit 100
2.
Enable ARP black hole routing on the device.
<Device> system-view
[Device] arp resolving-route enable
IP network
Gateway
Device
VLAN 10
Host B
R&D
ARP attack protection
VLAN 20
Host C
Office
375
Host D

Advertisement

Table of Contents
loading

Table of Contents