R3102-R3103-HP 6600/HSR6600 Routers Security Command Reference
503
Parameters
disable: Disables ARP packet rate limit.
rate pps: ARP packet rate in pps, in the range of 5 to 8192.
drop: Discards the exceeded packets.
slot slot-number: Specifies the slot number of the card.
The following matrix shows the option and router compatibility:
Option 6602 HSR6602 6604/6608/6616
slot slot-number No Yes Yes
Examples
# Specify the ARP packet rate for the card in slot 1 as 50 pps, and exceeded packets are discarded.
<Sysname> system-view
[Sysname] arp rate-limit rate 50 drop slot 1
ARP packet source MAC consistency check
configuration commands
arp anti-attack valid-ack enable
Use arp anti-attack valid-check enable to enable ARP packet source MAC address consistency check on
the gateway.
Use undo arp anti-attack valid-check enable to restore the default.
Syntax
arp anti-attack valid-check enable
undo arp anti-attack valid-check enable
Default
ARP packet source MAC address consistency check is disabled.
Views
System view
Default command level
2: System level
Usage guidelines
After you execute the arp anti-attack valid-check enable command, the gateway device can filter out
ARP packets with the source MAC address in the Ethernet header different from the sender MAC address
in the ARP message.
Examples
# Enable ARP packet source MAC address consistency check.
<Sysname> system-view










