Qtech QSW-2900-24T-AC [118/209] Enable disable arp anti flood attack

7-116
QTECH(config)#show arp static
Display all ARP table item with the IP address being 192.168.0.100
QTECH(config)#show arp 192.168.0.100
7.2.2 Enable/disable ARP anti-flood attack
ARP anti-flood attack means to prevent the same MAC sending plenty of arp packets to influence handling for
normal ARP packet. After enabling this function, if the received ARP packet number of fixed source MAC address is
beyond configured threshold, it is thought the user of this MAC address is ARP attacking and system will filter this
MAC address for delivering anti-attack table item. After delivering the anti-attack table item, this user is banned. By
default, ARP anti-attack function is disabled. Use following command in global configuration mode to enable it:
Enable ARP anti-flood attack
QTECH(config)#arp anti-flood
Disable ARP anti-flood attack
QTECH(config)#no arp anti-flood
7.2.3 Configure deny action and threshold of ARP
anti-flood
ARP anti-flood attack has two kind of source mac deny for arp overspeedthe speed of sending arp packet is beyond
threshold : one is deny arp packet from this mac, the other is deny all packets from this mac. Configure following
command in global configuration mode
arp anti-flood action { deny-arp | deny-all } threshold rate-limit
Threshold range is from 1-100 pps. By default, the deny action is deny-arp and threshold is 16 pps.
Example
! Configure deny action to be all packets deny and threshold to be 10 pps
QTECH(config)#arp anti-flood action deny-all threshold 10
7.2.4 Configure ARP anti-flood recover-time

Содержание

Скачать
Случайные обсуждения