< Home

Rate Limiting on ARP Miss Messages

If a network device is flooded with IP packets that contain unresolvable destination IP addresses, the device generates a large number of ARP Miss messages. This is because the device has no ARP entry that matches the next hop of the route. IP packets (ARP Miss packets), which trigger ARP Miss messages, are sent to the control board for processing. The device generates and delivers many temporary ARP entries according to the ARP Miss messages, and sends a large number of ARP Request packets to the destination network. This increases CPU usage of the device and consumes considerable network bandwidth. As shown in Figure 1, the attacker sends IP packets with the unresolvable destination IP address 10.2.1.5/24 to the gateway.

Figure 1 ARP Miss

To avoid the preceding problems, the device takes measures to limit the rate of ARP Miss messages.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >