HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 244

Configuring ARP attack protection, Overview, ARP attack protection configuration task list

Page 244 highlights

Configuring ARP attack protection Overview Although ARP is easy to implement, it provides no security mechanism and is vulnerable to network attacks. An attacker can exploit ARP vulnerabilities to attack network devices in the following ways: • Acts as a trusted user or gateway to send ARP packets so the receiving devices obtain incorrect ARP entries. • Sends a large number of destination unreachable IP packets to have the receiving device busy with resolving destination IP addresses until its CPU is overloaded. • Sends a large number of ARP packets to overload the CPU of the receiving device. For more information about ARP attack features and types, see ARP Attack Protection Technology White Paper. ARP attacks and viruses are threatening LAN security. This chapter introduces multiple features to detect and prevent such attacks. ARP attack protection configuration task list Task Flood prevention User and gateway spoofing prevention Configuring ARP defense against IP packet attacks Configuring ARP source suppression Enabling ARP black hole routing Configuring ARP packet rate limit Configuring source MAC address based ARP attack detection Configuring ARP packet source MAC address consistency check Configuring ARP active acknowledgement Configuring ARP detection Remarks Optional. Configure this function on gateways (recommended). Optional. Configure this function on gateways (recommended). Optional. Configure this function on access devices (recommended). Optional. Configure this function on gateways (recommended). Optional. Configure this function on gateways (recommended). Optional. Configure this function on gateways (recommended). Optional. Configure this function on access devices (recommended). 234

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

234
Configuring ARP attack protection
Overview
Although ARP is easy to implement, it provides no security mechanism and is vulnerable to network
attacks. An attacker can exploit ARP vulnerabilities to attack network devices in the following ways:
Acts as a trusted user or gateway to send ARP packets so the receiving devices obtain incorrect ARP
entries.
Sends a large number of destination unreachable IP packets to have the receiving device busy with
resolving destination IP addresses until its CPU is overloaded.
Sends a large number of ARP packets to overload the CPU of the receiving device.
For more information about ARP attack features and types, see
ARP Attack Protection Technology White
Paper
.
ARP attacks and viruses are threatening LAN security. This chapter introduces multiple features to detect
and prevent such attacks.
ARP attack protection configuration task list
Task
Remarks
Flood prevention
Configuring
ARP
defense
against IP
packet
attacks
Configuring ARP source
suppression
Optional.
Configure this function on
gateways (recommended).
Enabling ARP black hole routing
Optional.
Configure this function on
gateways (recommended).
Configuring ARP packet rate limit
Optional.
Configure this function on access
devices (recommended).
Configuring source MAC address based ARP
attack detection
Optional.
Configure this function on
gateways (recommended).
User and gateway
spoofing prevention
Configuring ARP packet source MAC address
consistency check
Optional.
Configure this function on
gateways (recommended).
Configuring ARP active acknowledgement
Optional.
Configure this function on
gateways (recommended).
Configuring ARP detection
Optional.
Configure this function on access
devices (recommended).