Arp Attack Defense Configuration; Configuring Arp Source Suppression; Introduction To Arp Source Suppression - H3C S5120-EI Series Operation Manual

Hide thumbs Also See for S5120-EI Series:
Table of Contents

Advertisement

3

ARP Attack Defense Configuration

When configuring ARP attack defense, go to these sections for information you are interested in:

Configuring ARP Source Suppression

Configuring ARP Defense Against IP Packet Attacks
Configuring ARP Active Acknowledgement
Configuring Source MAC Address Based ARP Attack Detection
Configuring ARP Packet Source MAC Address Consistency Check
Configuring ARP Packet Rate Limit
Configuring ARP Detection
Although ARP is easy to implement, it provides no security mechanism and thus is prone to network
attacks. Currently, ARP attacks and viruses are threatening LAN security. The device can provide
multiple features to detect and prevent such attacks. This chapter mainly introduces these features.
Configuring ARP Source Suppression

Introduction to ARP Source Suppression

If a device receives large numbers of IP packets from a host to unreachable destinations,
The device sends large numbers of ARP requests to the destination subnets, which increases the
load of the destination subnets.
The device continuously resolves destination IP addresses, which increases the load of the CPU.
To protect the device from such attacks, you can enable the ARP source suppression function. With the
function enabled, whenever the number of packets with unresolvable destination IP addresses from a
host within five seconds exceeds a specified threshold, the device suppresses the sending host from
triggering any ARP requests within the following five seconds.
Configuring ARP Source Suppression
Follow these steps to configure ARP source suppression:
To do...
Enter system view
Enable ARP source suppression
Set the maximum number of packets
with the same source IP address but
unresolvable destination IP
addresses that the device can
receive in five consecutive seconds
Use the command...
system-view
arp source-suppression enable
arp source-suppression limit
limit-value
3-1
Remarks
Required
Disabled by default.
Optional
10 by default.

Advertisement

Chapters

Table of Contents
loading

Table of Contents