If an interface receives a large number of ARP packets whose destination IP addresses are different from the IP address of this interface and sends these ARP packets to the CPU for processing, the CPU usage is high and the CPU cannot process services properly.
To prevent this issue, you can configure the device to directly forward ARP packets destined for other devices without sending them to the CPU. This improves the device's capability of defending against ARP flood attacks.
Only the S5720-HI, S5730-HI, S5731-H, S5731-S, S5731S-H, S5731S-S, S5732-H, S6720-HI, S6730-H, S6730S-H, S6730-S, and S6730S-S support this command.
Run system-view
The system view is displayed.
Run interface vlanif vlan-id
The VLANIF interface view is displayed.
Run arp optimized-passby enable
The device is configured not to send ARP packets destined for other devices to the CPU.
By default, a device does not send ARP packets destined for other devices to the CPU.