Huawei V200R001C01 Troubleshooting Manual page 301

Enterprise routers
Hide thumbs Also See for V200R001C01:
Table of Contents

Advertisement

Huawei AR2200-S Series Enterprise Routers
Troubleshooting
Common Causes
This fault is commonly caused by the following:
l
Troubleshooting Flowchart
An attacker sends a large number of destination unreachable packets to the AR2200-S. The
packets are sent to the CPU and trigger a large number of ARP Miss messages. In addition, the
AR2200-S sends ARP requests to trigger ARP learning, causing a high CPU usage.
Figure 10-8
Figure 10-8 Troubleshooting flowchart for IP address scanning
Troubleshooting Procedure
Issue 01 (2012-01-06)
An attacker sends a large number of destination unreachable packets to the AR2200-S, and
the packets trigger a large number of ARP Miss messages. In addition, the AR2200-S sends
ARP requests to trigger ARP learning, causing a high CPU usage.
shows the troubleshooting flowchart.
IP address
scanning attack
causes a high CPU
usage
Is ARP
Miss suppression
configured?
Yes
Is rate limit for
ARP Miss messages
too large?
No
Seek technical
support
NOTE
Saving the results of each troubleshooting step is recommended. If troubleshooting fails to correct the fault,
you will have a record of your actions to provide Huawei technical support personnel.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
No
Configure ARP Miss
suppression
Yes
Reduce the rate limit
10 Security
Yes
Is the fault
rectified?
No
Yes
Is the fault
rectified?
No
End
292

Advertisement

Table of Contents

Troubleshooting

loading

This manual is also suitable for:

Ar2200-s series

Table of Contents