Configuring Defense Against Arp Dos Attacks; Establishing The Configuration Task - Huawei Quidway S3700 Series Configuration Manual

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
by the ARP protocol. After the arp anti-attack packet-check sender-mac command is used,
the S3700 checks the source MAC addresses in the ARP packet header and Ethernet frame
header, and discards the packets with inconsistent source MAC addresses.
The ARP protocol defines that the ARP packet with consistent source MAC addresses in the
ARP packet header and the Ethernet frame header is a valid packet. However, such a packet may
be an attack packet. The S3700 provides the commands for source MAC address check, and
discards the packets that match certain conditions.
Pre-configuration Tasks
Before configuring source MAC address check, complete the following task:
l
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
arp anti-attack packet-check sender-mac
The S3700 checks the consistency between the source MAC addresses in the ARP packet header
and Ethernet frame header and discards the packet whose source MAC addresses are
inconsistent.
----End

4.4 Configuring Defense Against ARP DoS Attacks

If the S3700 receives a lot of ARP attack packets, the MAC address table overflows or the CPU
usage is high. The S3700 prevents ARP DoS attacks by discarding and limiting the rate of attack
packets.

4.4.1 Establishing the Configuration Task

This section describes the applicable scenario, pre-conditions, and data plan for the ARP DoS
attack defense function.
Applicable Environment
The ARP DoS attack packets can be ARP request packets, ARP Miss packets, and gratuitous
ARP packets.
prevent ARP DoS attacks.
Issue 01 (2011-07-15)
Setting the parameters of the link layer protocol and the IP addresses for interfaces so that
the link layer protocol is Up
Table 4-1
provides various attack scenarios and measures taken by the S3700 to
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
4 ARP Security Configuration
139

Advertisement

Table of Contents
loading

Table of Contents