Configuration Guide NFPP Configuration
For example,
Ruijie#show nfpp arp-guard scan statistics
ARP scan table has 4 record(s).
Ruijie# show nfpp arp-guard scan
VLAN interface IP address MAC address timestamp
---- -------- ---------- ----------- ----------
1 Gi0/1 N/A 0000.0000.0001 2008-01-23 16:23:10
2 Gi0/2 1.1.1.1 0000.0000.0002 2008-01-23 16:24:10
3 Gi0/3 N/A 0000.0000.0003 2008-01-23 16:25:10
4 Gi0/4 N/A 0000.0000.0004 2008-01-23 16:26:10
Total:4 record(s)
“timestamp” represents the time when the ARP scan was detected. For example,
“2008-01-23 16:23:10” represents that the ARP scan was detected at 16:23:10, Jan 23,
2008.
Ruijie# show nfpp arp-guard scan vlan 1 interface G 0/1 0000.0000.0001
VLAN interface IP address MAC address timestamp
---- -------- ---------- ----------- ----------
1 Gi0/1 N/A 0000.0000.0001 2008-01-23 16:23:10
Total:1 record(s)
IP-guard
IP-guard Overview
As is known to all, many hacker attacks and the network virus invasions begin
with the network scanning. To this end, a large amount of the scanning packets
take up the network bandwidth, leading to the abnormal network
communication.
Ruijie Layer-3 device provides the IP-guard function to prevent the attacks from
the hacker and the virus such as “Blaster”, reducing the CPU burden of the
layer-3 devices.
There are two types of the IP packet attack:
Scanning the destination IP address change: not only consumes the
network bandwidth and increases the device burden, but also is a prelude
of the hacker attack.