Arp Source-Mac Aging-Time - HP 5920 Command Reference Manual

Table of Contents

Advertisement

undo arp source-mac [ filter | monitor ]
Default
The source MAC address based ARP attack detection function is disabled.
Views
System view
Predefined user roles
network-admin
Parameters
filter: Generates log messages and discards subsequent ARP packets from the MAC address.
monitor: Only generates log message.
Usage guidelines
Configure this feature on the gateway devices.
This function enables the router to check the source MAC address of ARP packets received from the same
MAC address within 5 seconds against a specific threshold. If the threshold is exceeded, the router takes
the preconfigured method to handle the attack.
If neither the filter nor the monitor keyword is specified in the undo arp anti-attack source-mac command,
both handling methods are disabled.
Examples
# Enable the source MAC based ARP attack detection and specify the filter handling method.
<Sysname> system-view
[Sysname] arp source-mac filter

arp source-mac aging-time

Use arp source-mac aging-time to configure the aging time for ARP attack entries.
Use undo arp anti-attack source-mac aging-time to restore the default.
Syntax
arp source-mac aging-time time
undo arp source-mac aging-time
Default
The aging time for ARP attack entries is set to 300 seconds (5 minutes).
Views
System view
Predefined user roles
network-admin
294

Advertisement

Table of Contents
loading

This manual is also suitable for:

59005920 series5900 series

Table of Contents