R2511-HP MSR Router Series Security Command Reference(V5)

470
Default command level
1: Monitor level
Parameters
interface interface-type interface-number: Displays ARP attack entries detected on the interface.
|: Filters command output by specifying a regular expression. For more information about regular
expressions, see Fundamentals Configuration Guide.
begin: Displays the first line that matches the specified regular expression and all lines that follow.
exclude: Displays all lines that do not match the specified regular expression.
include: Displays all lines that match the specified regular expression.
regular-expression: Specifies a regular expression, a case-sensitive string of 1 to 256 characters.
Usage guidelines
If you do not specify any interface, the display arp anti-attack source-mac command displays ARP attack
entries detected on all interfaces.
Examples
# Display the ARP attack entries detected by source MAC-based ARP attack detection.
<Sysname> display arp anti-attack source-mac
Source-MAC VLAN ID Interface Aging-time
23f3-1122-3344 4094 GE1/1 10
23f3-1122-3355 4094 GE1/2 30
23f3-1122-33ff 4094 GE1/3 25
23f3-1122-33ad 4094 GE1/4 30
23f3-1122-33ce 4094 GE1/5 2
ARP packet source MAC consistency check
configuration commands
arp anti-attack valid-ack enable
Use arp anti-attack valid-check enable to enable ARP packet source MAC address consistency check on
the gateway.
Use undo arp anti-attack valid-check enable to restore the default.
Syntax
arp anti-attack valid-check enable
undo arp anti-attack valid-check enable
Default
ARP packet source MAC address consistency check is disabled.
Views
System view