Licensing Requirements and Limitations for ARP Security
This section describes licensing requirements and limitations for ARP security.
Involved Network Elements
Other network elements are not required.
Licensing Requirements
ARP security is a basic function of the switch, and as such is controlled by the license for basic software functions. The license for basic software functions has been loaded and activated before delivery. You do not need to manually activate it.
Version Requirements
Product Model |
Minimum Version Required |
---|---|
CE12804/CE12808/CE12812 |
V100R001C00 |
CE12816 |
V100R003C00 |
CE12804S/CE12808S |
V100R005C00 |
CE12804E/CE12808E/CE12816E |
V200R002C50 |
For details about the mapping between software versions and switch models, see the Hardware Query Tool.
Software version evolution: V100R001C00 -> V100R002C00 -> V100R003C00 -> V100R003C10 -> V100R005C00 -> V100R005C10 -> V100R006C00 -> V200R001C00 -> V200R002C50 -> V200R003C00 -> V200R005C00 -> V200R005C10 -> V200R019C00 -> V200R019C10
Feature Limitations
Do not enable the gratuitous ARP packet discarding function on a network-side interface.
If dynamic ARP entry learning is disabled on an interface, traffic forwarding may fail on this interface.
After dynamic ARP entry learning is disabled on an interface, the system will not automatically delete the ARP entries that were learned previously on this interface. You can delete or retain these dynamic ARP entries as required.
When the DAI is enabled in a VLAN, the transparent transmission of protocol packets does not take effect in this VLAN.
(For the CE12800E that has the FD-X series cards installed) When ARP rate limiting is configured on an interface and DAI is configured in a VLAN, ARP rate limiting does not take effect.
(For the CE12800E that has the FD-X series cards installed) After ARP rate limiting is configured for an inter-card LAG, if the accumulative rate of ARP packets sent by the interfaces on different cards reaches the upper limit but the rate of ARP packets sent by a single card does not reach the upper limit, the ARP rate limiting function does not take effect.
(For the CE12800E that has the FD-X series cards installed) If both interface-based ARP rate limiting and sFlow/NetStream are configured, interface-based ARP rate limiting is inaccurate. The maximum number of ARP packets sent from interfaces to the CPU is the ARP rate limit plus the number of ARP packets sampled by sFlow/NetStream.
- After ARP rate limiting is enabled on all interfaces, port-based automatic local attack defense for ARP does not take effect.