Configuring Source Ip Address-Based Arp Miss Packet Suppression - Huawei AR1200-S Configuration Manual

Enterprise routers
Hide thumbs Also See for AR1200-S:
Table of Contents

Advertisement

Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
----End
6.5.4 Configuring Source IP Address-based ARP Miss Packet
Suppression
This section describes how to configure source IP address-based ARP Miss packet suppression.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
arp-miss speed-limit source-ip maximum maximum
The rate limit of ARP Miss packets is set.
Step 3 (Optional) Run:
arp-miss speed-limit source-ip ip-address maximum maximum
The rate limit of ARP Miss packets with a specified source IP address is set.
After the preceding configurations are complete, the rate limit of ARP Miss packets with a
specified source IP address is specified by maximum in step 3, and the rate limit of ARP Miss
packets with other source IP addresses is specified by maximum in step 2.
If the rate limit of ARP packets is 0, ARP Miss packets are not suppressed. By default, the rate
limit of ARP Miss packets is 5 pps.
----End
Issue 02 (2012-03-30)
By default, rate limiting of ARP packets is disabled.
4.
Run:
arp anti-attack rate-limit packet-number [ interval-value ]
The rate limit duration and the rate limit of ARP packets are set.
After the rate limit duration and the rate limit of ARP packets are set, ARP packets
whose rate exceeds the rate limit in the rate limit duration are discarded. By default,
the rate limit of ARP packets is 100 and the rate limit duration of ARP packets is 1s.
5.
(Optional) Run:
arp anti-attack rate-limit alarm enable
The alarm function for ARP packets that are discarded when the rate of ARP packets
exceeds the rate limit is enabled.
By default, the alarm function for ARP packets that are discarded when the rate of
ARP packets exceeds the rate limit is disabled.
6.
(Optional) Run:
arp anti-attack rate-limit alarm threshold threshold
The alarm threshold for the number of ARP packets discarded when the rate of ARP
packets exceeds the rate limit is set.
By default, the alarm threshold for the number of ARP packets discarded is 100.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
6 ARP Security Configuration
139

Advertisement

Table of Contents
loading

Table of Contents