Configuring Arp Packet Rate Limit; Configuration Guidelines; Configuration Procedure - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Configuring ARP packet rate limit

The ARP packet rate limit feature allows you to limit the rate of ARP packets delivered to the CPU.
An ARP detection enabled device will send all received ARP packets to the CPU for inspection.
Processing excessive ARP packets will make the device malfunction or even crash. To solve this
problem, configure ARP packet rate limit.

Configuration guidelines

Configure this feature when ARP detection, ARP snooping, ARP fast-reply, or MFF is enabled, or
when ARP flood attacks are detected.

Configuration procedure

This task sets a rate limit for ARP packets received on an interface. When the receiving rate of ARP
packets on the interface exceeds the rate limit, those packets are discarded.
You can enable sending notifications to the SNMP module or enable logging for ARP packet rate
limit.
If notification sending is enabled, the device sends the highest threshold-crossed ARP packet
rate within the sending interval in a notification to the SNMP module. You must use the
snmp-agent target-host command to set the notification type and target host. For more
information about notifications, see Network Management and Monitoring Command
Reference.
If logging for ARP packet rate limit is enabled, the device sends the highest threshold-crossed
ARP packet rate within the sending interval in a log message to the information center. You can
configure the information center module to set the log output rules. For more information about
information center, see Network Management and Monitoring Configuration Guide.
To configure ARP packet rate limit:
Step
1.
Enter system view.
2.
(Optional.) Enable
notification sending for ARP
packet rate limit.
3.
(Optional.) Enable logging for
ARP packet rate limit.
4.
(Optional.) Set the
notification and log message
sending interval.
5.
Enter Layer 2 Ethernet
interface or Layer 2
aggregate interface view.
6.
Enable ARP packet rate limit
and set the rate limit.
NOTE:
If you enable notification sending and logging for ARP packet rate limit on a Layer 2 aggregate
interface, the features apply to all aggregation member ports.
Command
system-view
snmp-agent trap enable arp
[ rate-limit ]
arp rate-limit log enable
arp rate-limit log interval
seconds
interface interface-type
interface-number
arp rate-limit [ pps ]
431
Remarks
N/A
By default, notification sending for
ARP packet rate limit is disabled.
By default, logging for ARP packet
rate limit is disabled.
By default, the device sends
notifications and log messages at an
interval of 60 seconds.
N/A
By default, ARP packet rate limit is
enabled.
The default rate limit is 750 pps.

Advertisement

Table of Contents
loading

Table of Contents