Huawei Quidway S9300 Configuration Manual page 197

Terabit routing switch
Table of Contents

Advertisement

Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
# Enable the IP source guard function on GE 1/0/2 connected to the attacker.
[Quidway] interface gigabitethernet 1/0/2
[Quidway-GigabitEthernet1/0/2] arp anti-attack check user-bind enable
[Quidway-GigabitEthernet1/0/2] arp anti-attack check user-bind check-item ip-
address mac-address
[Quidway-GigabitEthernet1/0/2] quit
Step 2 Configure the check items of the static binding table.
# Configure Client in the static binding table.
[Quidway] user-bind static ip-address 10.0.0.1 mac-address 0001-0001-0001
interface gigabitethernet 1/0/1 vlan 10
Step 3 Configure the alarm function for discarded packets.
# Set the alarm threshold of the ARP packets discarded because they do not match the binding
table.
[Quidway] arp anti-attack check user-bind alarm threshold 80
Step 4 Verify the configuration.
Run the display this command, and you can view the global alarm threshold set for the ARP
packets discarded because they do not match the binding table. The alarm threshold takes effect
on all interfaces.
<Quidway> display this
#
arp anti-attack check user-bind alarm threshold 80
Run the display arp anti-attack check user-bind interface command, and you can view the
configuration of the IP source guard function on the interface.
<Quidway> display arp anti-attack check user-bind interface gigabitethernet 1/0/1
arp anti-attack check user-bind enable
arp anti-attack check user-bind alarm enable
ARP packet drop count = 0
<Quidway> display arp anti-attack check user-bind interface gigabitethernet 1/0/2
arp anti-attack check user-bind enable
arp anti-attack check user-bind alarm enable
ARP packet drop count = 20
The preceding information indicates that GE 1/0/1 does not discard ARP packets, whereas GE
1/0/2 has discarded ARP packets. It indicates that the anti-attack function takes effect.
----End
Configuration Files
#
sysname Quidway
#
vlan batch 10
#
arp anti-attack check user-bind alarm threshold 80
#
user-bind static ip-address 10.0.0.1 mac-address 0001-0001-0001 interface
gigabitethernet 1/0/1 vlan 10
#
interface gigabitethernet 1/0/1
arp anti-attack check user-bind enable
arp anti-attack check user-bind check-item ip-address mac-address
#
interface gigabitethernet 1/0/2
Issue 06 (2010–01–08)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
4 ARP Security Configuration
4-27

Advertisement

Table of Contents
loading

Table of Contents