Network requirements – H3C Technologies H3C WX3000E Series Wireless Switches User Manual

Page 345

Advertising
background image

331

Step Command

Remarks

5.

Configure protected MAC
addresses.

arp anti-attack source-mac
exclude-mac mac-address&<1-10>

Optional.
No protected MAC address is

configured by default.

NOTE:

After an ARP attack detection entry expires, ARP packets sourced from the MAC address in the entry can
be processed normally.

Displaying and maintaining source MAC address based ARP
attack detection

Task Command

Remarks

Display attacking MAC addresses detected
by source MAC address based ARP attack

detection.

display arp anti-attack source-mac
[ interface interface-type

interface-number ] [ | { begin |

exclude | include }
regular-expression ]

Available in any
view

Source MAC address based ARP attack detection

configuration example

Network requirements

As shown in

Figure 141

, the hosts access the Internet through a gateway (Device). If malicious users send

a large number of ARP requests to the gateway, the gateway may crash and cannot process requests
from the clients. To solve this problem, configure source MAC address based ARP attack detection on the

gateway.

Advertising