Qtech QSW-3900-24-SFP-AC [166/245] Anti flood arp

Qtech QSW-3900-48-SFP-DC [166/245] Anti flood arp
QTECH Software Configuration Manual
12-165
12.4 Anti-flood ARP
ARP anti-flood attack means to prevent the same MAC sending plenty of arp packets to influence handling
for normal ARP packet. After enabling this function, if the received ARP packet number of fixed source MAC address
is beyond configured threshold, it is thought the user of this MAC address is ARP attacking and system will filter this
MAC address for delivering anti-attack table item. After delivering the anti-attack table item, this user is banned.
By default, ARP anti-attack function is disabled.
12.5 ARP configuration list
Configuration list is as following :
· Add and delete ARP table item
· Display ARP table item
· Configure ARP aging time
· Display ARP aging time
· Display ARP table item
· Enable/disable ARP anti-flood attack
· Configure deny action and threshold of ARP anti-flood
· Configure ARP anti-flood recover-time
· ARP anti-flood MAC recover
· Display ARP anti-flood attack information
· Enable/disable ARP anti-spoofing
· Configure unknown ARP packet handling strategy
· Enable/disable ARP anti-spoofing valid-check
· Enable/disable ARP anti-spoofing deny-disguiser
· Display ARP anti-spoofing
12.5.1 Add and delete ARP table item
Use this command can add or delete a static or dynamic ARP table item. ARP table item not only include
corresponding relations of IP and MAC, but also the local VLAN and port number the frame with keyword MAC
being destination address has passed.
Add a static ARP table item with the IP address being 192.168.0.100MAC address being 00 : 01 : 02 : 03 :
04 : 05the corresponded VLAN interface being 1and port number being 3 :
QTECH(config)#arp 192.168.0.100 00 : 01 : 02 : 03 : 04 : 05 1 0/3
Delete the corresponded ARP table item of IP address 192.168.0.100 :
QTECH(config)#no arp 192.168.0.100
Delete all static ARP table item :
QTECH(config)#no arp static
Delete all dynamic ARP table item :
QTECH(config)#no arp dynamic
Delete all ARP table item :
QTECH(config)#no arp all
12.5.2 Display ARP table item
Use this command to display static, dynamic, specified IP address or all ARP table item.
Display all ARP table item :
show arp all

Содержание

Скачать