940
Syntax
arp source-mac
{
filter | monitor
}
undo arp source-mac
[
filter
|
monitor
]
Default
The source MAC-based ARP attack detection feature is disabled.
Views
System view
Predefined user roles
network-admin
Parameters
filter
: Generates log messages and discards subsequent ARP packets from the MAC address.
monitor
: Only generates log messages.
Usage guidelines
Configure this feature on the gateways.
This feature checks the number of ARP packets delivered to the CPU. If the number of ARP packets
from the same MAC address within 5 seconds exceeds a threshold, the device takes the
preconfigured method to handle the attack.
If you do not specify both the
filter
and
monitor
keywords in the
undo arp source-mac
command,
the command disables this feature.
Examples
# Enable the source MAC-based ARP attack detection feature and specify the filter handling method.
<Sysname> system-view
[Sysname] arp source-mac filter
arp source-mac aging-time
Use
arp source-mac aging-time
to set the aging time for ARP attack entries.
Use
undo arp source-mac aging-time
to restore the default.
Syntax
arp source-mac aging-time time
undo arp source-mac aging-time
Default
The aging time for ARP attack entries is 300 seconds.
Views
System view
Predefined user roles
network-admin
Parameters
time
: Sets the aging time for ARP attack entries, in the range of 60 to 6000 seconds.
Examples
# Set the aging time for ARP attack entries to 60 seconds.
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...