ddos-guard arp

Drops malformed ARP packets that may indicate a DDoS attack.
Syntax
ddos-guard arp enabledrop
ddos-guard arp enable mac counter timer
no ddos-guard arp enable drop
no ddos-guard arp enable mac counter timer
Command Default

By default, ARP packets are not dropped nor sent for analysis.

Parameters
drop
Drops all ARP packets suspected of being DDoS Gratuitous ARP attack packets.
mac counter timer
The malformed ARP packets are sent to the CPU for analysis for a specified duration, which can range from 1 to 30 seconds.
Modes

Global configuration mode

Usage Guidelines

This command is supported on ICX 8200 devices only.

The no form of the command disables the DDoS GARP check for or analysis of DDoS Gratuitous ARP packets.

Examples

The following example enables the dropping of packets suspected of being part of a DDoS Gratuitous ARP attack.

device# configure terminal
device(config)# ddos-guard arp enable drop

The following example shows how to send the suspected ARP packets to the CPU for analysis for a specified duration of 10 seconds.

device# configure terminal
device(config)# ddos-guard arp enable mac counter timer 10 
History
Release version Command history
10.0.20a This command was introduced.