3Com 8807 Configuration Manual page 75

8800 series
Hide thumbs Also See for 8807:
Table of Contents

Advertisement

c
Configuring Whether
the Switch Sends
Unreachable Packets
configure static ARP entries that have only IP addresses. The switch will
automatically fill the MAC address in the ARP mapping entries so that only users
configured with static ARP entries can have access to the network.
IP address protection configuration
The tasks of IP address protection configuration include:
Configuring auto-fill ARP address
Enabling IP address protection
Table 55 Configure IP address protection
Operation
Enter system view
Configure auto-fill ARP
address
Enter VLAN interface view
Enable IP address protection
View the IP address protection
status of the current VLAN
interface
CAUTION:
The MAC address auto filling function is enabled only when the IP address
protection function is enabled on the interface.
Once after the initial auto filling of ARP address, the user-configured static ARP
entry becomes a normal static ARP entry and cannot be filled again.
When receiving an IP packet whose TTL is 1, the switch sends an unreachable
packet to the sending end. However, if an attacker continuously sends IP packets
whose TTLs are less than or equal to 1 to the switch, the switch keeps sending
unreachable packets to the attacker. In this case, the switch CPU is under attack.
When receiving an IP packet whose TTL is less than or equal to 1, the switch sends
the ICMP packet "time exceeded" to the network management system instead of
sending an unreachable packet to the sending end, thus avoiding attack on the
CPU.
Table 56 Configure whether the switch sends unreachable packets
Operation
Enter system view
Configure that the switch
sends the ICMP message
"time exceeded" to the
network management system
when the switch receives an IP
packet whose TTL is less than
or equal to 1
Command
system-view
arp static ip-address
interface Vlan-interface
vlan-id
ip-protect enable
display this
Command
system-view
ip icmp-time-exceed enable
Configuring IP Address
Description
-
Optional
-
By default, the IP address
protection function is disabled
on VLAN interface
You can carry out the display
this command in any view
Description
-
By default, the switch sends
the ICMP message "time
exceeded" to the network
management system
75

Hide quick links:

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the 8807 and is the answer not in the manual?

Subscribe to Our Youtube Channel

This manual is also suitable for:

88108814

Table of Contents