Configuring Arp Anti-Attack; Establishing The Configuration Task - Huawei Quidway S9300 Configuration Manual

Terabit routing switch v100r001c03
Table of Contents

Advertisement

Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Example
Run the display arp learning strict command, and you can view the configuration of strict ARP
entry learning.
<Quidway> display arp learning strict
The global configuration:arp learning strict
interface
------------------------------------------------------------
Vlanif100
Vlanif200
------------------------------------------------------------
Total:2
force-enable:1
force-disable:1
Run the display arp-limit [ interface interface-type interface-number ] [ vlan vlan-id ]
command, and you can view the maximum number of ARP entries that can be learned by an
interface or a VLAN.
<Quidway> display arp-limit interface GigabitEthernet 1/0/10
interface
---------------------------------------------------------------------------
GigabitEthernet1/0/10
GigabitEthernet1/0/10
GigabitEthernet1/0/10
GigabitEthernet1/0/10
GigabitEthernet1/0/10
GigabitEthernet1/0/10
GigabitEthernet1/0/10
GigabitEthernet1/0/10
---------------------------------------------------------------------------
Total:8
<Quidway> display arp-limit vlan 3
interface
---------------------------------------------------------------------------
GigabitEthernet1/0/10
---------------------------------------------------------------------------

4.4 Configuring ARP Anti-Attack

This section describes how to configure the ARP anti-attack function.

4.4.1 Establishing the Configuration Task

4.4.2 Preventing the ARP Address Spoofing Attack
4.4.3 Preventing the ARP Gateway Duplicate Attack
4.4.4 Preventing the Man-in-the-Middle Attack
4.4.5 (Optional) Configuring the S9300 to Discard Gratuitous ARP Packets
4.4.6 Configuring DHCP to Trigger ARP Learning
4.4.7 Enabling Log and Alarm Functions for Potential Attacks
4.4.8 Checking the Configuration
4.4.1 Establishing the Configuration Task
Issue 01 (2009-07-28)
LimitNum
1000
1000
1000
1000
1000
1000
1000
1000
LimitNum
1000
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
LearningStrictState
force-disable
force-enable
VlanID
LearnedNum(Mainboard)
3
0
4
0
5
0
6
0
7
0
8
0
9
0
10
0
VlanID
LearnedNum(Mainboard)
3
0
4 ARP Security Configuration
4-7

Advertisement

Table of Contents
loading

Table of Contents