Default Settings for ARP Security
Table 10-5 describes the default settings for ARP security.
Parameter |
Default Setting |
---|---|
Rate limit on ARP packets based on source MAC addresses |
The maximum rate of ARP packets from each source MAC address is set to 0, that is, the rate of ARP packets is not limited based on the source MAC address. |
Rate limit on ARP packets based on source IP addresses |
The device allows a maximum of 50 ARP packets from the same source IP address to pass through per second. |
Rate limit on ARP packets based on destination IP addresses |
The maximum rate of ARP packets sent to each destination IP address is set to 500 pps, that is, a maximum of 500 ARP packets with the same destination IP address are allowed to pass through per second. |
Rate limit on ARP packets globally and in a VLAN |
Disabled |
Rate limit on ARP Miss messages based on source IP addresses |
The device can process a maximum of 50 ARP Miss messages triggered by IP packets from the same source IP address per second. |
Rate limit on ARP Miss messages globally, in a VLAN, or on an interface |
|
Aging time of temporary ARP entries |
5 seconds |
Gratuitous ARP packet discarding |
Disabled |
Strict ARP learning |
Disabled |
Interface-based ARP entry limit |
The maximum number of ARP entries that an interface can dynamically learn is the same as the number of ARP entries supported by the device. |
ARP entry fixing |
Disabled |
DAI |
Disabled |
MAC address consistency check in an ARP packet |
Disabled |