Common Causes
This fault is commonly caused by the following:
l
An attacker sends a large number of destination unreachable packets to the AR2200-S, and
the packets trigger a large number of ARP Miss messages. In addition, the AR2200-S sends
ARP requests to trigger ARP learning, causing a high CPU usage.
Troubleshooting Flowchart
An attacker sends a large number of destination unreachable packets to the AR2200-S. The
packets are sent to the CPU and trigger a large number of ARP Miss messages. In addition, the
AR2200-S sends ARP requests to trigger ARP learning, causing a high CPU usage.
shows the troubleshooting flowchart.
Figure 10-8
Troubleshooting flowchart for IP address scanning
IP address
scanning attack
causes a high CPU
usage
Yes
Is the fault
rectified?
No
Yes
End
No
Is ARP
Miss suppression
configured?
Configure ARP Miss
suppression
No
Seek technical
support
Is rate limit for
ARP Miss messages
too large?
Reduce the rate limit
Yes
Is the fault
rectified?
No
Yes
Troubleshooting Procedure
NOTE
Saving the results of each troubleshooting step is recommended. If troubleshooting fails to correct the fault,
you will have a record of your actions to provide Huawei technical support personnel.
Huawei AR2200-S Series Enterprise Routers
Troubleshooting
10 Security
Issue 01 (2012-01-06)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
292