No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

Configuration Guide - Security

CloudEngine 8800, 7800, 6800, and 5800 V200R005C10

This document describes the configurations of Security, including ACL, local attack defense, MFF, attack defense, traffic suppression and storm control, ARP security, Port security, DHCP snooping, ND snooping, PPPoE+, IPSG, SAVI, separating the management plane from the service plane, security risks.
Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
Configuring ARP Rate Limiting on All Interfaces

Configuring ARP Rate Limiting on All Interfaces

Context

When a device processes a large number of ARP packets, the CPU may be overloaded and cannot afford other services. Therefore, the device needs to limit the rate of ARP packets to protect CPU resources.

After the function of limiting ARP packet rate is enabled, you can run the commands in the system view to set an ARP rate limit for all interfaces. If the number of ARP packets received by an interface within one second exceeds the limit, the device discards the excess ARP packets.

If the arp anti-attack rate-limit command has been executed in the system view, the rate limit specified in the command is the upper limit for the total number of ARP packets on all interfaces. If the arp anti-attack rate-limit interface command has been executed in the system view, the rate limit specified in the command is the upper limit for the number of ARP packets on each interface.

NOTE:
  • When a CE6810LI functions as a leaf switch, ARP rate limiting for all interfaces cannot be configured on the leaf switch's interfaces.

  • CE6870EI and CE6875EI do not support arp rate limiting for all interfaces.

  • On a switch, after ARP rate limiting is enabled on all interfaces, port-based automatic local attack defense for ARP does not take effect.

Procedure

  1. Run system-view

    The system view is displayed.

  2. Run arp anti-attack rate-limit interface limit

    The rate limit for ARP packets is set.

    By default, ARP rate limit on all interfaces is 0. That is, the ARP packet rate on all interface is not limited.

  3. Run commit

    The configuration is committed.

Translation
Download
Updated: 2019-04-20

Document ID: EDOC1100074765

Views: 22973

Downloads: 93

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Share
Previous Next