l
If no ARP entry is displayed, go to step 2.
Step 2
Run the
display cpu-defend statistics
packet-type
arp-request
command to view the statistics
about ARP requests.
l
If the count of dropped ARP requests is 0, go to step 8.
l
If the count of dropped ARP requests is not 0, the rate of ARP requests exceeds the CPCAR
rate limit and excess ARP requests are discarded. Go to step 3.
Step 3
Run the
display cpu-usage
command to check the CPU usage of the main control board.
l
If the CPU usage is in the normal range but ARP requests are discarded, the rate limit is too
small. Go to step 4.
l
If the CPU usage is high, the CPU may be attacked by ARP packets. Go to step 5.
Step 4
Run the
packet-type
command in the attack defense policy view to increase the rate limit for
ARP requests and apply the attack defense policy.
Step 5
Capture packets on the user-side interface, and find the attacker according to the source addresses
of ARP requests.
If a large number of ARP requests are sent from a source address, the AR2200-S considers the
source address to be an attack source. Add the source address to the blacklist or configure a
blackhole MAC address entry to discard ARP requests sent by the attacker.
Step 6
Run the
arp speed-limit source-ip
command in the system view to set the rate limit for ARP
packets from the attack source.
By default, ARP packet suppression based on source IP addresses is enabled, and the maximum
rate of ARP requests is limited to 5 pps. After the rate of ARP requests reaches this limit, the
AR2200-S discards subsequent ARP requests.
Step 7
If the fault persists, collect the following information and contact Huawei technical support
personnel:
l
Results of the preceding troubleshooting procedure
l
Configuration file, log file, and alarm file of the AR2200-S
----End
Relevant Alarms and Logs
Relevant Alarms
l
1.3.6.1.4.1.2011.5.25.165.2.2.2.3
l
1.3.6.1.4.1.2011.5.25.165.2.2.2.4
l
1.3.6.1.4.1.2011.5.25.165.2.2.2.5
l
1.3.6.1.4.1.2011.5.25.165.2.2.2.6
l
1.3.6.1.4.1.2011.5.25.165.2.2.2.11
Relevant Logs
None.
10.2.4 IP Address Scanning Occurs
Huawei AR2200-S Series Enterprise Routers
Troubleshooting
10 Security
Issue 01 (2012-01-06)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
291