Configuring Arp Defense Against Ip Packet Attacks; Introduction; Configuring Arp Source Suppression; Enabling Arp Black Hole Routing - HP 12500 Series Configuration Manual

Routing
Table of Contents

Advertisement

Task

Configuring ARP defense against IP packet attacks

Introduction

If a switch receives a large number of IP packets from a host to unreachable destinations, the following
situations can occur:
The switch sends a large number of ARP requests to the destination subnets, and thus the load of the
destination subnets increases.
The switch keeps trying to resolve destination IP addresses, increasing the load of the CPU.
To protect the switch from IP packet attacks, you can enable the ARP source suppression function or ARP
black hole routing function.
If the packets have the same source address, you can enable the ARP source suppression function. With
the function enabled, you can set a threshold for the number of ARP requests that a sending host can
trigger in 5 seconds with packets with unresolvable destination IP addresses. When the number of ARP
requests exceeds that threshold, the switch suppresses the sending host from triggering any ARP requests
in the following 5 seconds.
If the packets have various source addresses, you can enable the ARP black hole routing function. After
receiving an IP packet whose destination IP address cannot be resolved by ARP, the switch with this
function enabled immediately creates a black hole route and simply drops all packets matching the route
during the aging time of the black hole route.

Configuring ARP source suppression

Step
1.
Enter system view.
2.
Enable ARP source suppression.
3.
Set the maximum number of packets with the
same source IP address but unresolvable
destination IP addresses that the switch can
receive in five consecutive seconds.

Enabling ARP black hole routing

Step
1.
Enter system view.
2.
Enable
routing.
Configuring ARP detection
Command
system-view
ARP
black
hole
arp resolving-route enable
Remarks
Optional.
Configure this function on access
devices (recommended).
Command
system-view
arp source-suppression enable
arp source-suppression limit
limit-value
266
Remarks
N/A
Disabled by default.
Optional.
10 by default.
Remarks
N/A
Optional.
Enabled by default.

Advertisement

Table of Contents
loading

Table of Contents