set arpinspection filter
SecureStack C2 Configuration Guide 17-23
Parameters
Defaults
Rate=15packetspersecond
BurstInterval=1second
Mode
Switchcommand,read‐write.
Usage
Toprotectthe switchagainstDHCPattackswhenDAIisenabled,theDAIap plication enforcesa
ratelimitforARPpacketsreceivedonuntrustedinterfaces.DAImonitorsthereceiverateoneach
interfaceseparately.Ifthereceiverateexceedsthelimitconfiguredwiththiscommand,DAI
disablestheinterface,whicheffectively
bringsdowntheinterface.Youcanusethesetportenable
commandtoreenabletheport.
Youcanconfigureboththerateandtheburstinterval.Thedefaultrateis15ppsoneachuntrusted
interfacewitharangeof0to100pps.Thedefaultburstintervalis1
secondwitharangeto1to15
seconds..TheratelimitcannotbesetontrustedinterfacessinceARPpacketsreceivedontrusted
interfacesdonotcometotheCPU.
Example
Thisexamplesetstherateto20packetspersecondandtheburstintervalto2secondsonports
ge.1.1andge.1.2.
C2(su)->set arpinspection limit port ge.1.1-2 rate 20 burst interval 2
set arpinspection filter
UsethiscommandtocreateanARPACLandthentoassignanACLtoaVLAN,optionallyasa
staticmapping.
Syntax
set arpinspection filter name {permit ip host sender-ipaddr mac host
sender-macaddr | vlan vlan-range [static]}
Parameters
port‐string Specifiestheportorportstowhichtoapplytheseratelimiting
parameters.
none ConfiguresnolimitonincomingARPpackets.
ratepps Specifiesaratelimitinpacketspersecond.Thevalueofppscanrange
from0to100packetspersecond.
burstintervalsecs Specifiesaburstintervalin
seconds.Thevalueofsecscanrangefrom1
to15seconds.
name Specifiesthe nameoftheARPACL.
permit Specifiesthatapermitruleisbeingcreated.
iphostsender‐ipaddr SpecifiestheIPaddressintherulebeingcreated.