发现交换机的4号单板上存在大量ARP报文丢包。
配置攻击溯源识别攻击源。
<HUAWEI> system-view [~HUAWEI] cpu-defend policy policy1 [*HUAWEI-cpu-defend-policy-policy1] auto-defend enable [*HUAWEI-cpu-defend-policy-policy1] auto-defend attack-packet sample 5 //每5个报文抽样识别一次,抽样值过小会消耗过多CPU [*HUAWEI-cpu-defend-policy-policy1] auto-defend threshold 30 //报文达30pps即被识别为攻击,若攻击源较多可调低该值 [*HUAWEI-cpu-defend-policy-policy1] auto-defend trace-type source-mac //基于源MAC进行攻击源识别 [*HUAWEI-cpu-defend-policy-policy1] auto-defend protocol arp //针对ARP攻击进行识别 [*HUAWEI-cpu-defend-policy-policy1] quit [*HUAWEI] cpu-defend-policy policy1 [*HUAWEI] commit
服务热线
1391-024-6332