Configuring ARP Rate Limiting on All Interfaces
Context
When a device processes a large number of ARP packets, the CPU may be overloaded and cannot afford other services. Therefore, the device needs to limit the rate of ARP packets to protect CPU resources.
After the function of limiting ARP packet rate is enabled, you can run the commands in the system view to set an ARP rate limit for all interfaces. If the number of ARP packets received by an interface within one second exceeds the limit, the device discards the excess ARP packets.
If the arp anti-attack rate-limit command has been executed in the system view, the rate limit specified in the command is the upper limit for the total number of ARP packets on all interfaces. If the arp anti-attack rate-limit interface command has been executed in the system view, the rate limit specified in the command is the upper limit for the number of ARP packets on each interface.
- Only the 12800E that has the FD-X series cards installed supports arp rate limiting for all interfaces.
On a switch, after ARP rate limiting is enabled on all interfaces, port-based automatic local attack defense for ARP does not take effect.