R211x-HP Flexfabric 11900 Security Command Reference

Table Of Contents
302
ARP attack protection commands
The ARP attack protection feature is available on Layer 2 and Layer 3 Ethernet interfaces and VLAN
interfaces. The term "interface" in this chapter collectively refers to these types of interfaces. You can use
the port link-mode command to configure an Ethernet port as a Layer 2 or Layer 3 interface (see Layer
2—LAN Switching Configuration Guide).
Unresolvable IP attack protection commands
arp resolving-route enable
Use arp resolving-route enable to enable ARP blackhole routing.
Use undo arp resolving-route enable to disable ARP blackhole routing.
Syntax
arp resolving-route enable
undo arp resolving-route enable
Default
ARP blackhole routing is enabled.
Views
System view
Predefined user roles
network-admin
mdc-admin
Usage guidelines
Configure this feature on the gateways.
If a device receives a large number of unresolvable IP packets from a host, the following situations can
occur.
The device sends a large number of ARP requests, overloading the target subnets.
The device keeps trying to resolve destination IP addresses, overloading its CPU.
If the IP packets have different source addresses, you can enable the ARP blackhole routing function.
After receiving an unresolvable IP packet, the device creates a blackhole route destined for the target IP
address and drops all the matching packets until the blackhole route ages out.
Examples
# Enable ARP blackhole routing.
<Sysname> system-view
[Sysname] arp resolving-route enable