HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 263

Source MAC address based ARP attack detection configuration commands, arp anti-attack source-mac

Page 263 highlights

Parameters disable: Disables ARP packet rate limit. rate pps: Specifies the ARP packet rate in pps, in the range of 50 to 500. drop: Discards the exceeded packets. Description Use arp rate-limit to configure or disable ARP packet rate limit on an interface. Use undo arp rate-limit to restore the default. By default, ARP packet rate limit is enabled, and the ARP packet rate limit is 100 pps. Examples # Specify the ARP packet rate on layer 2 Ethernet port GigabitEthernet 1/0/1 as 50 pps, and exceeded packets will be discarded. system-view [Sysname] interface gigabitethernet 1/0/1 [Sysname-GigabitEthernet1/0/1] arp rate-limit rate 50 drop Source MAC address based ARP attack detection configuration commands arp anti-attack source-mac Syntax arp anti-attack source-mac { filter | monitor } View undo arp anti-attack source-mac [ filter | monitor ] System view Default level 2: System level Parameters filter: Specifies the filter mode. monitor: Specifies the monitor mode. Description Use arp anti-attack source-mac to enable source MAC address based ARP attack detection and specify the detection mode. Use undo arp anti-attack source-mac to restore the default. By default, source MAC address based ARP attack detection is disabled. After you enable this feature, the device checks the source MAC address of ARP packets received from the VLAN. It detects an attack when one MAC address sends more ARP packets in five seconds than the specified threshold. Upon detecting an attack, the device does the following: 254

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291

254
Parameters
disable
: Disables ARP packet rate limit.
rate
pps
: Specifies the ARP packet rate in pps, in the range of 50 to 500.
drop
: Discards the exceeded packets.
Description
Use
arp rate-limit
to configure or disable ARP packet rate limit on an interface.
Use
undo arp rate-limit
to restore the default.
By default, ARP packet rate limit is enabled, and the ARP packet rate limit is 100 pps.
Examples
# Specify the ARP packet rate on layer 2 Ethernet port GigabitEthernet 1/0/1 as 50 pps, and exceeded
packets will be discarded.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] arp rate-limit rate 50 drop
Source MAC address based ARP attack detection
configuration commands
arp anti-attack source-mac
Syntax
arp anti-attack source-mac
{
filter
|
monitor
}
undo arp anti-attack source-mac
[
filter
|
monitor
]
View
System view
Default level
2: System level
Parameters
filter
: Specifies the
filter
mode.
monitor
: Specifies the
monitor
mode.
Description
Use
arp anti-attack source-mac
to enable source MAC address based ARP attack detection and specify
the detection mode.
Use
undo arp anti-attack source-mac
to restore the default.
By default, source MAC address based ARP attack detection is disabled.
After you enable this feature, the device checks the source MAC address of ARP packets received from
the VLAN. It detects an attack when one MAC address sends more ARP packets in five seconds than the
specified threshold. Upon detecting an attack, the device does the following: