Configuring Arp Source Suppression; Introduction To Arp Source Suppression; Configuring Authorized Arp; Introduction To Authorized Arp - 3Com MSR 50 Series Configuration Manual

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

Configuring ARP
Source Suppression
Introduction to ARP
Source Suppression
Configuring ARP Source
Suppression
Configuring
Authorized ARP
Introduction to
Authorized ARP
To do...
Enable the gratuitous ARP
packet learning function
If hosts on a network attack the device by sending large amounts of IP packets
whose IP addresses cannot be resolved, the following consequences will be
resulted in:
The device sends large amounts of ARP request messages to the destination
subnet, which increases the load of the destination subnet.
The device continuously resolves destination IP addresses, which increase the
load of the CPU.
To protect the device against this kind of attack, you can enable the ARP source
suppression function. With the function enabled, whenever the number of
packets with unresolvable IP addresses that a host on the network sends to the
device within five seconds exceeds the specified threshold, the device drops all
subsequent packets with the same source IP address in another five coming
seconds. This helps in protecting the device against the attack.
To do...
Enter system view
Enable ARP source
suppression
Set the maximum number of
packets with the same source
IP address but unresolvable
destination IP addresses that
the device can receive in five
seconds
n
This feature is only supported on Layer 3 Ethernet interfaces.
Authorized ARP entries are generated based on DHCP leases or security entries for
DHCP clients.
Authorized ARP can prevent attacks from illegal clients, and allow only legal clients
to access network resources, thus enhancing product security. With authorized
ARP enabled, an interface is disabled from learning dynamic ARP entries.
Static ARP entries can overwrite authorized ARP entries, and authorized ARP
entries can overwrite dynamic ARP entries. But authorized ARP entries cannot

Configuring ARP Source Suppression

Use the command...
gratuitous-arp-learning
enable
Use the command...
system-view
arp source-suppression
enable
arp source-suppression
limit limit-value
555
Remarks
Required
Disabled by default.
Remarks
-
Required
Disabled by default
Optional
10 by default

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents