Tp-Link T1600G-28PS (TL-SG2424P) [571/754] Configuring arp defend

Tp-Link T1600G-28PS (TL-SG2424P) [571/754] Configuring arp defend
Configuration Guide 549
Configuring Network Security ARP Inspection Configurations
Switch#copy running-config startup-config
4.2.5 Configuring ARP Defend
With ARP Defend enabled, the switch can terminate receiving the ARP packets for 300 seconds
when the transmission speed of the legal ARP packet on the port exceeds the defined value so as
to avoid ARP Attack flood.
Follow these steps to configure ARP Defend:
Step 1 configure
Enter global configuration mode.
Step 2 interface [ fastEthernet
port |
range fastEthernet
port-list |
gigabitEthernet
port |
range
gigabitEthernet
port-list
]
Enter interface configuration mode.
Step 3 ip arp inspection
Enable the ARP defend feature on the port.
Step 4 ip arp inspection limit-rate
value
Specify the maximum number of the ARP packets can be received on the port per second.
value:
Specify the limit rate value. The valid values are from 10 to 100 pps (packets/second),
and the default value is 15.
Step 5 show ip arp inspection interface
(Optional) View the configurations and status of the ports.
Step 6 ip arp inspection recover
(Optional) For ports which the speed of receiving ARP packets has exceeded the limit, use
this command to restore the port from Discard status to Normal status.
Step 7 end
Return to privileged EXEC mode.
Step 8 copy running-config startup-config
Save the settings in the configuration file.
The following example shows how to enable ARP Defend and configure the ARP inspection limit-
rate as 20 pps on port 1/0/2:
Switch#configure
Switch(config)#interface gigabitEthernet 1/0/2
Switch(config-if)#ip arp inspection
Switch(config-if)#ip arp inspection limit-rate 20

Содержание

Похожие устройства

Скачать