Dropping Suspicious ARP Packets
On ICX 8200 switches, the following
commands can be entered in global configuration mode to drop suspect, malformed ARP
packets that may indicate a DDoS attack. To drop all malformed ARP packets, use the
ddos-guard arp enable
drop command. To send dropped packets to the CPU for analysis for a
specified duration, enter the ddos-guard arp enable mac counter
timer command.
- Enter the
configure terminalcommand to enter global configuration mode. - Enter the
ddos-guard arp enable dropcommand to enable the checking for and dropping of gratuitous ARP packets. - (Optional) Enter the
ddos-guard arp enable mac counter timercommand to send dropped ARP packets to the CPU for analysis for a specified duration, which can range from 1 to 30 seconds.