Huawei Quidway S3700 Series Configuration Manual page 179

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
Step 2 Configure the alarm function for discarded packets.
# Set the alarm threshold of the ARP packets discarded because they do not match the binding
table on Ethernet 0/0/1 connected to the client.
[Quidway-Ethernet0/0/1] arp anti-attack check user-bind alarm enable
[Quidway-Ethernet0/0/1] arp anti-attack check user-bind alarm threshold 80
[Quidway-Ethernet0/0/1] quit
# Set the alarm threshold of the ARP packets discarded because they do not match the binding
table on Ethernet 0/0/2 connected to the attacker.
[Quidway-Ethernet0/0/2] arp anti-attack check user-bind alarm enable
[Quidway-Ethernet0/0/2] arp anti-attack check user-bind alarm threshold 80
[Quidway-Ethernet0/0/2] quit
Step 3 Configure the check items of the static binding table.
# Configure Client in the static binding table.
[Quidway] user-bind static ip-address 10.0.0.1 mac-address 0001-0001-0001
interface ethernet 0/0/1 vlan 10
Step 4 Verify the configuration.
Run the display arp anti-attack configuration check user-bind interface command, and you
can view the configuration of the IP source guard function on the interface.
<Quidway> display arp anti-attack configuration check user-bind interface ethernet
0/0/1
arp anti-attack check user-bind enable
arp anti-attack check user-bind alarm enable
arp anti-attack check user-bind alarm threshold 80
arp anti-attack check user-bind check-item ip-address mac-address vlan
ARP packet drop count = 0
<Quidway> display arp anti-attack configuration check user-bind interface ethernet
0/0/2
arp anti-attack check user-bind enable
arp anti-attack check user-bind alarm enable
arp anti-attack check user-bind alarm threshold 80
arp anti-attack check user-bind check-item ip-address mac-address vlan
ARP packet drop count = 2442
The preceding information indicates that Ethernet 0/0/1 does not discard ARP packets, whereas
Ethernet 0/0/2 has discarded ARP packets. It indicates that the anti-attack function takes effect.
----End
Configuration Files
#
vlan batch 10
#
user-bind static ip-address 10.0.0.1 mac-address 0001-0001-0001 interface
ethernet 0/0/1 vlan 10
#
interface ethernet0/0/1
arp anti-attack check user-bind enable
arp anti-attack check user-bind check-item ip-address mac-address vlan
arp anti-attack check user-bind alarm enable
arp anti-attack check user-bind alarm threshold 80
#
interface ethernet0/0/2
arp anti-attack check user-bind enable
arp anti-attack check user-bind check-item ip-address mac-address vlan
arp anti-attack check user-bind alarm enable
arp anti-attack check user-bind alarm threshold 80
Issue 01 (2011-07-15)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
4 ARP Security Configuration
166

Advertisement

Table of Contents
loading

Table of Contents