EasyManua.ls Logo

Ruijie RG-S2900G-E Series - Page 746

Ruijie RG-S2900G-E Series
943 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Configuration Guide NFPP Configuration
Command
Function
Ruijie(config-nfpp)# end
Return to the privileged EXEC mode.
Ruijie# configure terminal
Enter the global configuration mode.
Ruijie# interface interface-name
Enter the interface configuration mode.
Ruijie(config-if)# nfpp nd-guard
enable
Enable the nd-guard on the interface. By
default, nd-guard is not enabled on the
interface.
Ruijie(config-if)# end
Return to the privileged EXEC mode.
Ruijie# show nfpp dhcpv6-guard
summary
Show the configurations.
Ruijie# copy running-config
startup-config
Save the configurations.
Caution
With the nd-guard disabled, the monitored hosts are
auto-cleared.
Port-based rate-limit and attack detection
You can configure the ND-guard rate-limit and attack threshold on the port. The
rate-limit value must be less than the attack threshold value. When the ND
packet rate on a port exceeds the limit, the ND packets are dropped. When the
ND packet rate on a port exceeds the attack threshold limit, the CLI prompts
and the TRAP packets are sent.
ND Snooping divides the port into the untrusted port and the trusted port, which
connect to the host and the gateway respectively. The rate-limit threshold for
the trusted port shall be higher than the one for the untrusted port because the
traffic for the trusted port is generally higher than the one for the untrusted port.
With the ND Snooping enabled, the ND Snooping advertises the ND-guard to
set the rate-limit threshold and the attack threshold of the ND packets on the
trusted port as 800pps and 900pps respectively.
For the rate-limit threshold configured by the ND Snooping and the one
configured by the administrator, the latter configured threshold value overwrites
the former configured one.
When the administrator saves the settings, the rate-limit threshold configured by
the ND Snooping saved into the configuration file.

Table of Contents

Related product manuals