User's Manual

Table Of Contents
Configuration Guide of XGS-5240-Series
32-4
clear anti-arpscan attack-list {ip < IP
Address > | all }
Clear the ARP limit of the specific host or
all the hosts manually.
clear anti-arpscan attack-history-list {i
p < IP Address > | all }
Clear the history attacks source
information of ARP scanning prevention
manually.
Admin Mode
debug anti-arpscan [port | ip]
no debug anti-arpscan [port | ip]
Enable or disable the debug switch of ARP
scanning prevention.
7. Configure the action after above level-2 threshold
Command
Explanation
Global configuration Mode
anti-arpscan ip-based level2 action {is
olate | discard-ARP}
After above level-2 threshold, users can
configure ip business isolation and discard
ARP packets.
anti-arpscan ip-based arp-to-cpu spee
d <pps>
no anti-arpscan ip-based arp-to-cpu s
peed
Configure the rate of ARP send to CPU
when level-1 threshold overrun.
32.3 ARP Scanning Prevention Typical Examples
Fig 2-1 ARP scanning prevention typical configuration example
In the network topology above, port E1/1 of SWITCH B is connected to port E1/19 of
SWITCH A, the port E1/2 of SWITCH A is connected to file server (IP address is
SWITCH A
SWITCH B
PC PC
E1/1
E1/19
E1/2
Server
192.168.1.100/24
E1/2