Huawei Quidway S9300 Configuration Manual page 129

Terabit routing switch v100r001c03
Table of Contents

Advertisement

Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Configuration Roadmap
The configuration roadmap is as follows:
1.
2.
3.
4.
5.
6.
7.
Data Preparation
To complete the configuration, you need the following data:
l
l
l
l
l
l
l
Procedure
Step 1 Enable strict ARP learning.
<Quidway> system-view
[Quidway] arp learning strict
Step 2 Configure interface-based ARP entry restriction.
# The number of limited ARP entries on each interface is 20. The following lists the configuration
of GE 1/0/1, and the configurations of other interfaces are the same as the configuration of GE
1/0/1.
[Quidway] interface gigabitethernet 1/0/1
[Quidway-GigabitEthernet1/0/1] arp-limit vlan 10 maximum 20
[Quidway-GigabitEthernet1/0/1] quit
Step 3 Enable the ARP anti-spoofing function.
# Set the ARP anti-spoofing mode to fixed-mac to prevent ARP spoofing attacks initiated by
User 1.
[Quidway] arp anti-attack entry-check fixed-mac enable
Step 4 Enable the ARP anti-attack function for preventing ARP packets with the bogus gateway
address.
Issue 01 (2009-07-28)
Enable strict ARP learning.
Enable interface-based ARP entry restriction.
Enable the ARP anti-spoofing function.
Enable the ARP anti-attack function for preventing ARP packets with the bogus gateway
address.
Configure the rate suppression function for ARP packets.
Configure the rate suppression function for ARP Miss packets.
Enable log and alarm functions for potential attacks.
Number of limited ARP entries on the interface being 20
Anti-spoofing mode used to prevent attacks that is initiated by User 1 being fixed-mac
IP address of the server being 2.2.2.2/24
IP address of User 4 that sends a large number of ARP packets being 2.2.4.2/24
Maximum suppression rate for ARP packets of User 4 being 200 pps and maximum
suppression rate for ARP packets of other users being 300 pps
Maximum suppression rate for ARP Miss packets of common users being 400 pps and
maximum suppression rate for ARP Miss packets on the server being 1000 pps
Interval for writing an ARP log and sending an alarm being 30 seconds
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
4 ARP Security Configuration
4-21

Advertisement

Table of Contents
loading

Table of Contents