Huawei Quidway S9300 Configuration Manual page 193

Terabit routing switch
Table of Contents

Advertisement

Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
3.
4.
5.
6.
7.
Data Preparation
To complete the configuration, you need the following data:
l
l
l
l
l
l
l
Procedure
Step 1 Enable strict ARP learning.
<Quidway> system-view
[Quidway] arp learning strict
Step 2 Configure interface-based ARP entry restriction.
# The number of limited ARP entries on each interface is 20. The following lists the configuration
of GE 1/0/1, and the configurations of other interfaces are the same as the configuration of GE
1/0/1.
[Quidway] interface gigabitethernet 1/0/1
[Quidway-GigabitEthernet1/0/1] arp-limit vlan 10 maximum 20
[Quidway-GigabitEthernet1/0/1] quit
Step 3 Enable the ARP anti-spoofing function.
# Set the ARP anti-spoofing mode to fixed-mac to prevent ARP spoofing attacks initiated by
User 1.
[Quidway] arp anti-attack entry-check fixed-mac enable
Step 4 Enable the ARP anti-attack function for preventing ARP packets with the bogus gateway
address.
# Enable the ARP anti-attack function for preventing ARP packets with the bogus gateway
address to prevent User 1 from sending ARP packets with the bogus gateway address.
[Quidway] arp anti-attack gateway-duplicate enable
Step 5 Configure the rate suppression function for ARP packets.
Issue 06 (2010–01–08)
Enable the ARP anti-spoofing function.
Enable the ARP anti-attack function for preventing ARP packets with the bogus gateway
address.
Configure the rate suppression function for ARP packets.
Configure the rate suppression function for ARP Miss packets.
Enable log and alarm functions for potential attacks.
Number of limited ARP entries on the interface being 20
Anti-spoofing mode used to prevent attacks that is initiated by User 1 being fixed-mac
IP address of the server being 2.2.2.2/24
IP address of User 4 that sends a large number of ARP packets being 2.2.4.2/24
Maximum suppression rate for ARP packets of User 4 being 200 pps and maximum
suppression rate for ARP packets of other users being 300 pps
Maximum suppression rate for ARP Miss packets of common users being 400 pps and
maximum suppression rate for ARP Miss packets on the server being 1000 pps
Interval for writing an ARP log and sending an alarm being 30 seconds
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
4 ARP Security Configuration
4-23

Advertisement

Table of Contents
loading

Table of Contents