Huawei Quidway S3700 Series Configuration Manual page 176

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
interface
------------------------------------------------------------
------------------------------------------------------------
Total:0
force-enable:0
force-disable:0
You can use the display arp-limit command to check the maximum number of ARP entries
learned by the interface.
<Quidway> display arp-limit interface ethernet 0/0/1
interface
---------------------------------------------------------------------------
Ethernet0/0/1
---------------------------------------------------------------------------
Total:1
You can use the display arp anti-attack configuration all command to check the configuration
of ARP anti-attack.
<Quidway> display arp anti-attack configuration all
ARP anti-attack entry-check mode: fixed-MAC
ARP gateway-duplicate anti-attack function: enabled
ARP anti-attack log-trap-timer: 30seconds
(The log and trap timer of speed-limit, default is 0 and means disabled.)
ARP rate-limit configuration:
-------------------------------------------------------------------------------
Globle configuration:
Interface configuration:
Vlan configuration:
-------------------------------------------------------------------------------
ARP miss rate-limit configuration:
-------------------------------------------------------------------------------
Globle configuration:
Interface configuration:
Vlan configuration:
-------------------------------------------------------------------------------
ARP speed-limit for source-IP configuration:
IP-address
------------------------------------------------------------------------
2.2.4.2
Others
------------------------------------------------------------------------
1 specified IP addresses are configured, spec is 1024 items.
ARP miss speed-limit for source-IP configuration:
IP-address
------------------------------------------------------------------------
2.2.2.2
Others
------------------------------------------------------------------------
1 specified IP addresses are configured, spec is 1024 items.
You can use the display arp packet statistics command to view the number of discarded ARP
packets and the number of learned ARP entries. In addition, you can also use the display arp
anti-attack gateway-duplicate item command to view information about attacks from the
packets with the forged gateway address on the current network.
<Quidway> display arp packet statistics
ARP Pkt Received:
ARP Learnt Count:
ARP Pkt Discard For Limit:
Issue 01 (2011-07-15)
LimitNum
20
suppress-rate(pps)(rate=0 means function disabled)
10
15
suppress-rate(pps)(rate=0 means function disabled)
50
20
sum
167
sum
8
sum
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
LearningStrictState
VlanID
LearnedNum(Mainboard)
10
0
5
4 ARP Security Configuration
163

Advertisement

Table of Contents
loading

Table of Contents