Configuration Example - HP 6125G Configuration Manual

Security configuration guide
Hide thumbs Also See for 6125G:
Table of Contents

Advertisement

Task
Display attacking MAC addresses
detected by source MAC address based
ARP attack detection.

Configuration example

Network requirements
As shown in
a large number of ARP requests to the gateway, the gateway may crash and cannot process requests
from the clients. To solve this problem, configure source MAC address based ARP attack detection on the
gateway.
Figure 73 Network diagram
ARP attack protection
Host A
Configuration considerations
An attacker may forge a large number of ARP packets by using the MAC address of a valid host as the
source MAC address. To prevent such attacks, configure the gateway in the following steps:
Enable source MAC address based ARP attack detection and specify the filter mode.
1.
Set the threshold.
2.
Set the age timer for detection entries.
3.
Configure the MAC address of the server as a protected MAC address so that it can send ARP
4.
packets
Configuration procedure
# Enable source MAC address based ARP attack detection and specify the filter mode.
<Device> system-view
Figure
73, the hosts access the Internet through a gateway (Device). If malicious users send
IP network
Host B
Command
display arp anti-attack source-mac { slot
slot-number | interface interface-type
interface-number } [ | { begin | exclude |
include } regular-expression ]
Gateway
Device
Host C
239
Remarks
Available in any view
Server
0012-3f 86-e 94c
Host D

Advertisement

Table of Contents
loading

This manual is also suitable for:

6125 blade switch series

Table of Contents