Configuring Arp Packet Rate Limit; Configuring Source Mac-Based Arp Attack Detection - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

Configuring ARP packet rate limit

This feature allows you to limit the rate ARP packets are delivered to the CPU. For example, if an attacker
sends a large number of ARP packets to an ARP detection enabled device, the CPU of the device
becomes overloaded because all of the ARP packets are redirected to the CPU for inspection. As a result,
the device is unable to provide other functions and can even crash. To solve this problem, configure ARP
packet rate limit.
Configure this feature when ARP detection, ARP snooping, or MFF is enabled, or when ARP flood attacks
are detected.
Configuring ARP packet rate limit
This task sets a rate limit for ARP packets received on an interface.
To configure ARP packet rate limit:
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet interface or
Layer 2 aggregate interface view.
3.
Configure or disable ARP packet rate
limit.
Configuring source MAC-based ARP attack
detection
This feature checks the number of ARP packets received from the same MAC address within five seconds
against a specified threshold. If the threshold is exceeded, the device adds the MAC address in an ARP
attack entry. Before the entry is aged out, the device handles the attack by using either of the following
methods:
Monitor—Generates log messages.
Filter—Generates log messages and filters out subsequent ARP packets from that MAC address.
You can exclude the MAC addresses of some gateways and servers from detection. This feature will not
inspect ARP packets from those devices even if they are attackers.
To configure source MAC-based ARP attack detection:
Step
1.
Enter system view.
2.
Enable source MAC-based
ARP attack detection and
specify the handling method.
3.
Configure the threshold.
Command
system-view
interface interface-type
interface-number
arp rate-limit { disable | rate pps
drop }
Command
system-view
arp anti-attack source-mac { filter |
monitor }
arp anti-attack source-mac
threshold threshold-value
254
Remarks
N/A
N/A
Enabled by default, and
the ARP packet rate limit is
100 pps.
Remarks
N/A
Disabled by default.
Optional.
By default, the threshold is 50.

Advertisement

Table of Contents
loading

Table of Contents