Configuring The S3700 To Send Gratuitous Arp Packets - Huawei Quidway S3700 Series Configuration Manual

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
----End

4.4.7 Configuring the S3700 to Send Gratuitous ARP Packets

By configuring the S3700 to send gratuitous ARP packets, you can ensure that user packets are
sent to the correct gateway and prevent malicious attackers from intercepting user packets.
Context
The S3700 periodically sends ARP request packets with the destination IP address being the
gateway address to update the gateway MAC address in ARP entries of users on the network.
This ensures that packets of users on the network are forwarded to the gateway and prevents
hackers from intercepting these packets.
When the S3700 function as the gateway, you can enable the function of sending gratuitous ARP
packets globally or on a VLANIF interface. If the function of sending gratuitous ARP packets
is enabled globally and on a VLANIF interface simultaneously, the function enabled on the
VLANIF interface takes effect.
Procedure
Step 1 Run:
system-view
Issue 01 (2011-07-15)
The interface view is displayed.
3.
Run:
arp anti-attack rate-limit enable
Rate limit of ARP packets is enabled.
By default, rate limit of ARP packets is disabled.
4.
Run:
arp anti-attack rate-limit packet-number [ interval-value ]
The rate limit duration and the maximum rate of ARP packets are set.
After the rate limit duration and the maximum rate of ARP packets are set, ARP
packets whose rate exceeds the maximum rate in the rate limit duration are discarded.
By default, the maximum rate of ARP packets is 100 and the rate limit duration of
ARP packets is 1s.
5.
(Optional) Run:
arp anti-attack rate-limit alarm enable
The alarm function for the ARP packets discarded when the rate of ARP packets
exceeds the maximum rate is enabled.
By default, the alarm function is disabled when the rate of ARP packets exceeds the
maximum rate.
6.
(Optional) Run:
arp anti-attack rate-limit alarm threshold threshold
The alarm threshold for the number of ARP packets discarded when the rate of ARP
packets exceeds the maximum rate is set.
By default, the alarm threshold for the number of ARP packets discarded is 100.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
4 ARP Security Configuration
147

Advertisement

Table of Contents
loading

Table of Contents