Dropping Suspicious ARP Packets

On ICX 8200 switches, the following commands can be entered in global configuration mode to drop suspect, malformed ARP packets that may indicate a DDoS attack. To drop all malformed ARP packets, use the ddos-guard arp enable drop command. To send dropped packets to the CPU for analysis for a specified duration, enter the ddos-guard arp enable mac counter timer command.

  1. Enter the configure terminal command to enter global configuration mode.
    device# configure terminal
  2. Enter the ddos-guard arp enable drop command to enable the checking for and dropping of gratuitous ARP packets.
    device(config)# ddos-guard arp enable drop     
  3. (Optional) Enter the ddos-guard arp enable mac counter timer command to send dropped ARP packets to the CPU for analysis for a specified duration, which can range from 1 to 30 seconds.
    device(config)# ddos-guard arp enable mac counter timer 10