Configuring Arp Defense Against Ip Packet Attacks; Configuring Arp Source Suppression; Enabling Arp Black Hole Routing; Displaying And Maintaining Arp Defense Against Ip Packet Attacks - HP A6600 Configuration Manual

Hide thumbs Also See for A6600:
Table of Contents

Advertisement

Configuring ARP defense against IP packet attacks

If the device receives a large number of IP packets from a host to unreachable destinations:
The device sends a large number of ARP requests to the destination subnets, and thus the load of
the destination subnets increases.
The device keeps trying to resolve destination IP addresses, which increases the load of the CPU.
To protect the device from IP packet attacks, enable the ARP source suppression function or ARP black
hole routing function.
If the packets have the same source address, enable the ARP source suppression function. With the
function enabled, whenever the number of ARP requests triggered by the packets with unresolvable
destination IP addresses from a host within 5 seconds exceeds a specified threshold, the device
suppresses the packets of the sending host from triggering any ARP requests within the following 5
seconds.
If the packets have various source addresses, enable the ARP black hole routing function. After receiving
an IP packet whose destination IP address cannot be resolved by ARP, the device with this function
enabled immediately creates a black hole route and simply drops all packets matching the route during
the aging time of the black hole route.

Configuring ARP source suppression

To do...
1.
Enter system view.
2.
Enable ARP source suppression.
3.
Set the maximum number of packets with the
same source IP address but unresolvable
destination IP addresses that the device can
receive in 5 consecutive seconds.

Enabling ARP black hole routing

To do...
1.
Enter system view.
2.
Enable ARP black hole
routing.
Displaying and maintaining ARP defense against IP packet
attacks
To do...
Display the ARP source suppression
configuration information
Command...
system-view
arp source-suppression enable
arp source-suppression limit
limit-value
Command...
system-view
arp resolving-route enable
Command...
display arp source-suppression [
| { begin | exclude | include }
regular-expression ]
416
Remarks
Required.
Disabled by default.
Optional
10 by default.
Remarks
Optional
Disabled by default
Remarks
Available in any view

Advertisement

Table of Contents
loading

Table of Contents