Huawei Quidway S9300 Configuration Manual page 131

Terabit routing switch v100r001c03
Table of Contents

Advertisement

Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
ARP speed-limit for source-IP configuration:
IP-address
------------------------------------------------------------------------
2.2.4.2
Others
------------------------------------------------------------------------
1 specified IP addresses are configured, spec is 1024 items.
ARP miss speed-limit for source-IP configuration:
IP-address
------------------------------------------------------------------------
2.2.2.2
Others
------------------------------------------------------------------------
1 specified IP addresses are configured, spec is 1024 items.
You can use the display arp packet statistics command to view the number of discarded ARP
packets and the number of learned ARP entries. In addition, you can also use the display arp
anti-attack gateway-duplicate item command to view information about attacks from the
packets with the forged gateway address on the current network.
<Quidway> display arp packet statistics
ARP Pkt Received:
ARP Learnt Count:
ARP Pkt Discard For Limit:
ARP Pkt Discard For SpeedLimit:
ARP Pkt Discard For Other:
----End
Configuration Files
#
sysname Quidway
#
vlan batch 10 20 30
#
arp speed-limit source-ip maximum 300
arp-miss speed-limit source-ip maximum 400
arp learning strict
arp anti-attack log-trap-timer 30
#
arp anti-attack entry-check fixed-mac enable
arp anti-attack gateway-duplicate enable
arp-miss speed-limit source-ip 2.2.2.2 maximum 1000
arp speed-limit source-ip 2.2.4.2 maximum 200
#
interface gigabitethernet 1/0/1
port hybrid pvid vlan 10
port hybrid tagged vlan 10
arp-limit vlan 10 maximum 20
#
interface gigabitethernet 1/0/2
port hybrid pvid vlan 20
port hybrid tagged vlan 20
arp-limit vlan 20 maximum 20
#
interface gigabitethernet 1/0/3
port hybrid pvid vlan 30
port hybrid untagged vlan 30
arp-limit vlan 30 maximum 20
#
return
Issue 01 (2009-07-28)
suppress-rate(pps)(rate=0 means function disabled)
200
300
suppress-rate(pps)(rate=0 means function disabled)
1000
400
sum
167
sum
8
sum
sum
sum
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
4 ARP Security Configuration
5
0
3
4-23

Advertisement

Table of Contents
loading

Table of Contents