Dhcp Packet Rate Limit Configuration - 3Com 4500 PWR 26-Port Configuration Manual

Hide thumbs Also See for 4500 PWR 26-Port:
Table of Contents

Advertisement

42

DHCP Packet Rate Limit Configuration

Whe
n config
uring the DHCP packet rate limit function, go to t
in
terested in:
Introduc
tion to DHCP Packet Rate Limit
Configu
ring DHCP Packet Rate Limit
Rate Limit Configuration Example
Intro u
d ction to DHCP Packet Rate Limit
To prevent ARP attacks and attacks from unauthorized DHCP servers, ARP packets and DHCP
p
ackets will be processed by the switch CPU for validity checking. But, if attackers generate a large
number of ARP packets or DHCP packets, the switch CPU will be under extremely heavy load. As a
result, the switch cannot work normally and
S4500 series Ethernet switches support ARP and DHCP
port under attack to prevent hazardous impact on the device CPU. For details about ARP packet rate
limit, refer to
ARP Operati
f
unction.
After DHCP packet rate limit is enabl
p
ackets received on this port per s
the specified value, packets are passing the port at an over-high rate,
In this case, the swit
f
rom attacks.
In addition, the switch supports port state auto-recovery. After a port i
p
acket rate, it resumes automatically after a configurable period of time.
When both port state auto-recovery interval for over-high ARP packet rate and port state auto-recovery
interval for over-high DHCP packet rate are configured on a port, the shorter one will be the
auto-recovery time.
Con
figuring DHCP Packet Rate Limit
Configuring DHCP Packet Rate Limit
Follow these steps to configure rate limit of DHCP packets:
To do...
Enter system view
on in this ma
nual. The following des
ed on an Ethernet po
e
cond. If the number of DH
ch shu
ts down this p
ort so that it cannot re
Use the command...
system-view
hese
even goes down.
packet rate limit on a port and shut down the
cribes only the D
rt, the sw
CP pack
ceive a
42-1
sections for information you are
HCP packe
itch counts the numb
er of DHCP
ets received per second ex
which implie
s an attack to the port.
ny packet,
thus protect the switch
s shut down due to o
Remarks
t rate limit
ceeds
ver-high

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

4500 26-port4500 50-port

Table of Contents