beautypg.com

14 arp attack protection configuration, Arp attack protection overview, Arp attack protection configuration task list – H3C Technologies H3C S7500E Series Switches User Manual

Page 252: Arp attack protection configuration

background image

14-1

14

ARP Attack Protection Configuration

When configuring ARP attack Protection, go to these sections for information you are interested in:

z

Configuring ARP Defense Against IP Packet Attacks

z

Configuring ARP Active Acknowledgement

z

Configuring Source MAC Address Based ARP Attack Detection

z

Configuring ARP Packet Rate Limit

z

Configuring ARP Detection

ARP Attack Protection Overview

Although ARP is easy to implement, it provides no security mechanism and thus is prone to network

attacks. An attacker can send

z

ARP packets by acting as a trusted user or gateway. As a result, the receiving device obtains

incorrect ARP entries, and thus a communication failure occurs.

z

A large number of IP packets with unreachable destinations. As a result, the receiving device

continuously resolves destination IP addresses and thus its CPU is overloaded.

z

A large number of ARP packets to bring a great impact to the CPU.

For details about ARP attack features and types, refer to ARP Attack Protection Technology White

Paper.

Currently, ARP attacks and viruses are threatening LAN security. The device can provide multiple

features to detect and prevent such attacks. This chapter mainly introduces these features.

ARP Attack Protection Configuration Task List

Complete the following tasks to configure ARP attack Protection:

Task

Remarks

Configuring ARP

Source Suppression

Optional

Configure this function on gateways (recommended).

Flood prevention

Enabling ARP Black

Hole Routing

Optional

Configure this function on gateways (recommended).

Configuring ARP Active Acknowledgement

Optional

Configure this function on gateways (recommended).

Configuring Source MAC Address Based ARP

Attack Detection

Optional

Configure this function on gateways (recommended).