Verifying the Anti-ARP Flooding Configuration

This section describes how to check the configurations of Address Resolution Protocol (ARP) anti-flood functions.

Prerequisites

All ARP anti-flooding functions have been configured.

Procedure

  • Run the display arp learning strict command to check the configuration of strict ARP learning.
  • Run the display arp-limit [ interface interface-type interface-number ] [ vlan vlan-id ] command to check the configuration of ARP entry limit.
  • Run the display arp speed-limit { destination-ip | source-ip } [ slot slot-id ] command to check the configuration of ARP packet rate limit.
  • Run the display arp-miss speed-limit source-ip [ slot slot-id ] command to check the configuration of ARP Miss message rate limit.
  • Run the display arp-safeguard statistics slot slot-id command to check ARP bidirectional isolation statistics on an interface board.
  • Run the display arp rate-limit interface interface-type interface-number command to check the ARP packet rate limit on an interface.
  • Run the display arp attack interface interface-type interface-number command to check ARP attack information on an interface.
  • Run the display arp attack slot { slot-id | all } command to check ARP attack information on an interface board.
  • Run the display arp anti-attack record command to display information about discarded ARP packets whose rate exceeds the limit.
  • Run the display arp miss anti-attack record command to display information about discarded ARP Miss messages whose rate exceeds the limit.
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic