Huawei Quidway S3700 Series Configuration Manual page 175

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
Procedure
Step 1 Enable strict ARP learning.
<Quidway> system-view
[Quidway] arp learning strict
Step 2 Configure interface-based ARP entry restriction.
# The number of limited ARP entries on each interface is 20. The following lists the configuration
of Ethernet 0/0/1, and the configurations of other interfaces are the same as the configuration of
Ethernet 0/0/1.
[Quidway] interface ethernet 0/0/1
[Quidway-Ethernet0/0/1] arp-limit vlan 10 maximum 20
[Quidway-Ethernet0/0/1] quit
Step 3 Enable the ARP anti-spoofing function.
# Set the ARP anti-spoofing mode to fixed-mac to prevent ARP spoofing attacks initiated by
User 1.
[Quidway] arp anti-attack entry-check fixed-mac enable
Step 4 Enable the ARP anti-attack function for preventing ARP packets with the bogus gateway
address.
# Enable the ARP anti-attack function for preventing ARP packets with the bogus gateway
address to prevent User 1 from sending ARP packets with the bogus gateway address.
[Quidway] arp anti-attack gateway-duplicate enable
Step 5 Configure the rate suppression function for ARP packets.
# Set the suppression rate for ARP packets sent by User 4 to 10 pps. To prevent all users from
sending a large number of ARP packets incorrectly, set the suppression rate for ARP packets of
the system to 15 pps.
[Quidway] arp speed-limit source-ip maximum 15
[Quidway] arp speed-limit source-ip 2.2.2.4 maximum 10
Step 6 Configure the rate suppression function for ARP Miss packets.
# Set the suppression rate for ARP Miss packets of the system to 20 pps to prevent users from
sending a large number of IP packets with an unreachable destination IP address.
[Quidway] arp-miss speed-limit source-ip maximum 20
# Set the suppression rate for ARP Miss packets on the server to 50 pps to prevent the server
from sending a large number of IP packets with an unreachable destination IP address, and to
prevent communication on the network when the rate for the server to send IP packets with an
unreachable destination IP address is not as required.
[Quidway] arp-miss speed-limit source-ip 2.2.2.2 maximum 50
Step 7 Enable log and alarm functions for potential attacks.
[Quidway] arp anti-attack log-trap-timer 300
Step 8 Verify the configuration.
After the configuration, run the display arp learning strict command, and you can view
information about strict ARP learning.
<Quidway> display arp learning strict
The global configuration:arp learning strict
Issue 01 (2011-07-15)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
4 ARP Security Configuration
162

Advertisement

Table of Contents
loading

Table of Contents