Introduction To Arp Source Suppression; Configuring Arp - H3C S7500 Series Operation Manual

Hide thumbs Also See for S7500 Series:
Table of Contents

Advertisement

Operation Manual – ARP
H3C S7500 Series Ethernet Switches
Note:
Generally, ports in the same VLAN are interconnected at Layer 2 by default. So,
proxy ARP only processes inter-VLAN ARP requests and does not deal with
intra-VLAN ARP requests.
When isolate-user-vlan function is enabled on the Layer 2 switches connected with
the S7500, ports in the same VLAN are isolated with each other at Layer 2. To
provide Layer 3 connectivity between Layer 2 isolated ports in the same VLAN, you
need to enable the intra-VLAN proxy ARP on the S7500 to have proxy ARP process
intra-VLAN ARP requests.

1.1.8 Introduction to ARP Source Suppression

With the ARP source suppression function, the switch classifies incoming ARP packets
and limits the maximum number of ARP packets with the same type that can be sent to
the CPU in a time of time, so as to protect the CPU from being attacked by illegal ARP
packets generated by ARP scanning of a host to the whole network.
An S7500 series switch classifies incoming ARP packets into the following types:
Arbitrary ARP packets, whose source/destination IP addresses are not
distinguished
Pass-through ARP packets, whose source IP addresses are the same one and
destination IP addresses are not the IP address of the current switch
Locally-terminated ARP packets, whose source IP addresses are the same one
and destination addresses are the IP address of the current switch.
For each type, you can set the maximum number of ARP packets that can be sent to
the CPU in a unit of time on the switch. When the number of ARP packets received in a
unit of time exceeds the corresponding setting, the switch will regard the exceeding
ones as illegal ARP packets and discard them.

1.2 Configuring ARP

ARP entries in an S7500 series Ethernet switch falls into two types: static and dynamic,
as described in
Table 1-4 ARP entry
ARP entry
Static ARP entry
Dynamic ARP
entry
Table
1-4.
Generation method
Manually configured
Dynamically generated
1-6
Chapter 1 ARP Configuration
Maintenance method
Manual maintenance
A dynamic ARP entry ages out when
ARP aging timer expires.

Advertisement

Table of Contents
loading

Table of Contents