< Home

Defense Against ARP Flood Attacks

As shown in Figure 1, user hosts connect to the gateway through SwitchA and SwitchB. If a large number of ARP packets are broadcast on the network, the gateway cannot process other services due to CPU overload. Processing too many ARP packets will occupy considerable bandwidth, thus leading to network congestion and affecting network communication.

Figure 1 Defending against ARP flood attacks

To avoid the preceding problems, deploy ARP flood defense functions on the gateway, including rate limiting on ARP packets, rate limiting on ARP Miss messages, strict ARP learning, and ARP entry limiting.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
Next topic >