EasyManua.ls Logo

HPE FlexNetwork 5510 HI Series

HPE FlexNetwork 5510 HI Series
551 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
415
an ARP attack entry. Before the entry is aged out, the device handles the attack by using either of the
following methods:
MonitorOnly generates log messages.
FilterGenerates log messages and filters out subsequent ARP packets from that MAC
address.
You can exclude the MAC addresses of some gateways and servers from this detection. This feature
does not inspect ARP packets from those devices even if they are attackers.
Configuration procedure
To configure source MAC-based ARP attack detection:
Step
Command
Remarks
1. Enter system view.
system-view
N/A
2. Enable source MAC-based
ARP attack detection and
specify the handling method.
arp source-mac
{
filter
|
monitor
}
By default
, this feature is
disabled.
3. Set the threshold.
arp source-
mac threshold
threshold-value
The default threshold is 30.
4. Set the aging timer for ARP
attack entries.
arp source-mac aging-time
time
By default
, the lifetime is 300
seconds.
5. (Optional.)
Exclude specific
MAC addresses
from this
detection.
arp source-mac exclude-mac
mac-address&<1-10>
By default, no
MAC address is
excluded.
NOTE:
Whe
n an ARP attack entry is aged out
, ARP packets sourced from the MAC address in the entry can
be processed correctly.
Displaying and maintaining source MAC-based ARP attack
detection
Execute display commands in any view.
Task
Command
Display ARP attack entries detected by source
MAC-based ARP attack detection.
display arp source-mac
{
slot
slot-number |
interface
interface-type interface-number
}
Configuration example
Network requirements
As shown in Figure 123, the hosts access the Internet through a gateway (Device). If malicious users
send a large number of ARP requests to the gateway, the gateway might crash and cannot process
requests from the clients. To solve this problem, configure source MAC-based ARP attack detection
on the gateway.

Table of Contents

Other manuals for HPE FlexNetwork 5510 HI Series

Related product manuals