Enabling ARP black hole routing
To do...
1.
Enter system view.
2.
Enable ARP black hole
routing.
Displaying and maintaining ARP defense against IP packet
attacks
To do...
Display the ARP source suppression
configuration information
ARP defense against IP packet attack configuration example
Network requirements
As shown in
VLAN 20. The two areas each connect to the gateway (Device) through an access switch.
A large number of ARP requests are detected in the office area and are considered to be the result of an
IP flood attack. To prevent such attacks, configure ARP source suppression and ARP black hole routing.
Figure 73 Network diagram for configuring ARP defense against IP packet attacks
Use the command...
system-view
arp resolving-route enable
Figure
73, a LAN contains two areas: an R&D area in VLAN 10 and an office area in
Use the command...
display arp source-suppression [
| { begin | exclude | include }
regular-expression ]
225
Remarks
—
Optional
Enabled by default
Remarks
Available in any view