Configuring Rate Limit Of Arp Miss Packets - Huawei Quidway S3700 Series Configuration Manual

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
If the rate of ARP Miss packets from the specified IP address to this interface reaches the limit,
the S3700 delivers an ACL rule to discard the IP packets that trigger ARP Miss. The ACL rule
will be canceled after 50 seconds.
----End

4.4.5 Configuring Rate Limit of ARP Miss Packets

Context
If ARP Miss packets are triggered globally, in a VLAN, or on an interface continuously in a
period, a device is busy in broadcasting ARP request packets. The performance of the device is
thus degraded. After rate limit of ARP Miss packets is configured, the statistics on reported ARP
Miss packets are collected and then ARP Miss packets whose rate exceeds the maximum rate
are discarded.
Procedure
l
l
Issue 01 (2011-07-15)
Configuring rate limit of ARP Miss packets in the system view
1.
Run:
system-view
The system view is displayed.
2.
Run:
arp-miss anti-attack rate-limit enable
Rate limit of ARP Miss packets is enabled globally.
By default, ARP Miss packets is disabled globally.
3.
Run:
arp-miss anti-attack rate-limit packet-number [ interval-value ]
The rate limit duration and the maximum rate of ARP Miss packets are set.
After the rate limit duration and the maximum rate of ARP Miss packets are set, ARP
Miss packets whose rate exceeds the maximum rate in the rate limit duration are
discarded. By default, the maximum rate of ARP Miss packets is 100 and the rate limit
duration of ARP Miss packets is 1s.
4.
(Optional) Run:
arp-miss anti-attack rate-limit alarm enable
The alarm function for the ARP Miss packets discarded when the rate of ARP Miss
packets exceeds the maximum rate is enabled.
By default, the alarm function for the ARP Miss packets discarded when the rate of
ARP Miss packets exceeds the maximum rate is disabled.
5.
(Optional) Run:
arp-miss anti-attack rate-limit alarm threshold threshold
The alarm threshold for the number of ARP Miss packets discarded when the rate of
ARP Miss packets exceeds the maximum rate is set.
By default, the alarm threshold for the number of ARP Miss packets discarded is 100.
Configuring rate limit of ARP Miss packets in the VLAN view
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
4 ARP Security Configuration
143

Advertisement

Table of Contents
loading

Table of Contents