Optional) Configuring The S9300 To Discard Gratuitous Arp Packets - Huawei Quidway S9300 Configuration Manual

Terabit routing switch v100r001c03
Table of Contents

Advertisement

4 ARP Security Configuration
By default, the interfaces are not enabled with the IP source guard function.
Step 4 Run:
arp anti-attack check user-bind check-item { ip-address | mac-address | vlan }
The check items of ARP packets are configured.
By default, the check items consist of IP address, MAC address, VLAN, and interface. The
interface number of the ARP packet must be the same as the number of the interface where the
arp anti-attack check user-bind check-item command is run. The packets that do not match
the binding table are discarded.
Step 5 (Optional) Run:
arp anti-attack check user-bind alarm enable
The alarm function for the discarded ARP packets is enabled.
By default, the alarm function is disabled.
Step 6 (Optional) Run:
arp anti-attack check user-bind alarm threshold threshold
The alarm threshold of the number of ARP packets discarded because they do not match the
binding table is set.
By default, the alarm threshold is the same as the threshold set in arp anti-attack check user-
bind alarm threshold that is run in the system view. If the alarm threshold is not set in the
system view, the default threshold on the interface is 100.
----End
4.4.5 (Optional) Configuring the S9300 to Discard Gratuitous ARP
Packets
Context
If a large number of gratuitous ARP packets are sent to attack the S9300, the S9300 cannot
process valid ARP packets. You can configure the S9300 to discard the gratuitous ARP packets.
The function of discarding gratuitous ARP packets can be enabled in the system view or the
VLANIF interface view.
l
l
l
Procedure
l
4-10
If the function is enabled in the system view, all the interfaces of the S9300 discard the
gratuitous ARP packets.
If the function is enabled in the VLANIF interface view, the VLANIF interface discards
the gratuitous ARP packets.
Before enabling an interface to discard gratuitous ARP packets, you do not need to enable
the function globally.
Enabling the function of discarding gratuitous ARP packets globally
1.
Run:
system-view
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Issue 01 (2009-07-28)
*

Advertisement

Table of Contents
loading

Table of Contents