S1720, S2700, S5700, and S6720 Series Ethernet
Switches
Configuration Guide - Security Contents
Contents
About This Document................................................................................................................ ii
1 Security Features Supported in This Version.................................................................... 1
2 ACL Configuration................................................................................................................... 6
2.1 Overview of ACLs.................................................................................................................................................................... 6
2.2 Understanding ACLs............................................................................................................................................................... 8
2.2.1 ACL Fundamentals.............................................................................................................................................................. 8
2.2.2 ACL Classification.............................................................................................................................................................. 12
2.2.3 Step........................................................................................................................................................................................ 14
2.2.4 Matching Order.................................................................................................................................................................. 15
2.2.5 Matching Conditions........................................................................................................................................................ 19
2.2.6 Time Range.......................................................................................................................................................................... 28
2.2.7 Default ACL Actions and Mechanisms of Different Service Modules............................................................. 30
2.2.8 ACL Configuration Guidelines....................................................................................................................................... 38
2.3 Application Scenarios for ACLs.........................................................................................................................................41
2.3.1 Using an ACL to Control Telnet Login Rights.......................................................................................................... 41
2.3.2 Applying an ACL to SNMP to Filter NMSs................................................................................................................ 41
2.3.3 Using an ACL to Restrict Mutual Access Between Network Segments.......................................................... 42
2.3.4 Using an ACL to Prevent Certain Users from Accessing the Internet in the Specified Time Range..... 43
2.3.5 Using an ACL in QoS to Implement Traffic Policing............................................................................................. 44
2.3.6 Using an ACL to Filter OSPF Routes........................................................................................................................... 44
2.4 Licensing Requirements and Limitations for ACLs.................................................................................................... 45
2.5 Summary of ACL Configuration Tasks........................................................................................................................... 49
2.6 Default Settings for ACLs................................................................................................................................................... 53
2.7 Configuring and Applying a Basic ACL.......................................................................................................................... 53
2.7.1 (Optional) Creating a Time Range in Which an ACL Takes Effect................................................................... 53
2.7.2 Configuring a Basic ACL.................................................................................................................................................. 55
2.7.3 Applying a Basic ACL........................................................................................................................................................ 57
2.7.4 Verifying the ACL Configuration.................................................................................................................................. 61
2.8 Configuring and Applying an Advanced ACL.............................................................................................................. 61
2.8.1 (Optional) Creating a Time Range in Which an ACL Takes Effect...................................................................61
2.8.2 Configuring an Advanced ACL...................................................................................................................................... 61
2.8.3 Applying an Advanced ACL............................................................................................................................................ 66
Issue 12 (2020-11-15) Copyright © Huawei Technologies Co., Ltd. vi
S1720, S2700, S5700, and S6720 Series Ethernet
Switches
Configuration Guide - Security Contents
2.8.4 Verifying the ACL Configuration.................................................................................................................................. 69
2.9 Configuring and Applying a Layer 2 ACL..................................................................................................................... 69
2.9.1 (Optional) Creating a Time Range in Which an ACL Takes Effect................................................................... 69
2.9.2 Configuring a Layer 2 ACL............................................................................................................................................. 69
2.9.3 Applying a Layer 2 ACL................................................................................................................................................... 71
2.9.4 Verifying the ACL Configuration.................................................................................................................................. 72
2.10 Configuring and Applying a User-Defined ACL....................................................................................................... 73
2.10.1 (Optional) Creating a Time Range in Which an ACL Takes Effect................................................................ 73
2.10.2 Configuring a User-Defined ACL............................................................................................................................... 73
2.10.3 Applying a User-Defined ACL..................................................................................................................................... 76
2.10.4 Verifying the ACL Configuration................................................................................................................................ 77
2.11 Configuring and Applying a User ACL.........................................................................................................................77
2.11.1 (Optional) Creating a Time Range in Which an ACL Takes Effect................................................................ 77
2.11.2 Configuring a User ACL................................................................................................................................................ 77
2.11.3 Applying a User ACL...................................................................................................................................................... 80
2.11.4 Verifying the ACL Configuration................................................................................................................................ 81
2.12 Configuring and Applying a Basic ACL6..................................................................................................................... 81
2.12.1 (Optional) Creating a Time Range in Which an ACL6 Takes Effect.............................................................. 81
2.12.2 Configuring a Basic ACL6............................................................................................................................................. 82
2.12.3 Applying a Basic ACL6................................................................................................................................................... 84
2.12.4 Verifying the ACL6 Configuration..............................................................................................................................87
2.13 Configuring and Applying an Advanced ACL6......................................................................................................... 87
2.13.1 (Optional) Creating a Time Range in Which an ACL6 Takes Effect.............................................................. 87
2.13.2 Configuring an Advanced ACL6................................................................................................................................. 87
2.13.3 Applying an Advanced ACL6....................................................................................................................................... 90
2.13.4 Verifying the ACL6 Configuration..............................................................................................................................92
2.14 Maintaining ACLs............................................................................................................................................................... 92
2.14.1 Adjusting the Step of ACL Rules................................................................................................................................ 92
2.14.2 Displaying ACL Resources............................................................................................................................................ 93
2.14.3 Optimizing ACL Resources........................................................................................................................................... 93
2.14.4 Setting Alarm Threshold Percentage of ACL Resource Usage.........................................................................95
2.14.5 Configuring the Resource Mode of the Extended ACL Entry Space.............................................................. 96
2.14.6 Clearing ACL or ACL6 Statistics..................................................................................................................................97
2.15 Configuration Examples for ACLs................................................................................................................................. 97
2.15.1 Example for Using Basic ACLs to Restrict FTP Access Rights...........................................................................97
2.15.2 Example for Using Basic ACLs to Control Telnet Login Rights........................................................................ 99
2.15.3 Example for Applying Basic ACLs to SNMP to Filter NMSs........................................................................... 101
2.15.4 Example for Using Basic ACLs to Filter OSPF Routes...................................................................................... 104
2.15.5 Example for Using Advanced ACLs to Restrict Mutual Access Between Network Segments............ 108
2.15.6 Example for Using Advanced ACLs to Implement Unidirectional Access Control..................................112
2.15.7 Example for Using Advanced ACLs to Control Access to the Specified Server in the Specified Time
Range............................................................................................................................................................................................. 115
2.15.8 Example for Using Layer 2 ACLs to Block Network Access of the Specified Users............................... 120
Issue 12 (2020-11-15) Copyright © Huawei Technologies Co., Ltd. vii
S1720, S2700, S5700, and S6720 Series Ethernet
Switches
Configuration Guide - Security Contents
2.15.9 Example for Using Layer 2 ACLs in QoS to Implement Traffic Policing.................................................... 122
2.15.10 Example for Using User-Defined ACLs to Filter the Specified Packets....................................................125
2.15.11 Example for Using User ACLs to Control Network Access Rights of Enterprise's Internal Users
Based on Groups........................................................................................................................................................................ 128
2.15.12 Example for Using Advanced ACL6s to Filter Certain Types of IPv6 Packets........................................ 133
2.16 Troubleshooting ACLs..................................................................................................................................................... 136
2.16.1 Services Are Interrupted Due to Incorrect IP Address Wildcard Mask....................................................... 136
2.16.2 Users Cannot Access the Internet Because the DNS Server Address Is Blocked.................................... 136
2.16.3 Time Range-based ACL Does Not Take Effect Due to Incorrect System Time........................................137
2.16.4 Access Control Does Not Take Effect Due to Incorrect Direction of Traffic Policy................................ 138
2.17 FAQ About ACLs............................................................................................................................................................... 140
2.17.1 In Which Methods Can ACLs Be Delivered?........................................................................................................ 140
2.17.2 What Is the Relationship Between the permit/deny Rules in an ACL and Those in the Behavior of a
Traffic Policy?.............................................................................................................................................................................. 144
2.17.3 How Can I Apply an ACL to a VLAN?.................................................................................................................... 144
2.17.4 How Can I Apply an ACL to an Interface?........................................................................................................... 146
2.17.5 How Can I Check the Order in Which ACL Rules Take Effect?..................................................................... 147
2.17.6 How Can Unidirectional Access Control Be Implemented?........................................................................... 148
2.17.7 After a Traffic Policy Is Configured, Two ACL Rules Are Occupied Based on the display acl resource
Command Output. Why?........................................................................................................................................................ 149
2.17.8 How Are deny and permit in ACL Rules Used in Different Services?......................................................... 149
3 Local Attack Defense Configuration...............................................................................152
3.1 Overview of Local Attack Defense............................................................................................................................... 152
3.2 Licensing Requirements and Limitations for Local Attack Defense.................................................................. 156
3.3 Default Settings for Local Attack Defense................................................................................................................. 159
3.4 Configuring CPU Attack Defense ................................................................................................................................. 162
3.4.1 Creating an Attack Defense Policy............................................................................................................................ 163
3.4.2 Configuring a Blacklist.................................................................................................................................................. 163
3.4.3 Configuring a User-Defined Flow.............................................................................................................................. 164
3.4.4 Configuring a Rule for Sending Packets to the CPU........................................................................................... 165
3.4.5 (Optional) Configuring Dynamic CPCAR Adjustment for Protocol Packets............................................... 170
3.4.6 (Optional) Enabling Alarm Reporting for Packet Loss Caused by CPCAR Exceeding............................. 171
3.4.7 Specifying Interface Types for Protocol Packets................................................................................................... 172
3.4.8 Applying an Attack Defense Policy........................................................................................................................... 173
3.4.9 Verifying the CPU Attack Defense Configuration................................................................................................ 174
3.5 Configuring Attack Source Tracing............................................................................................................................... 175
3.5.1 Creating an Attack Defense Policy............................................................................................................................ 175
3.5.2 Configuring the Threshold for Attack Source Tracing........................................................................................ 176
3.5.3 Setting the Packet Sampling Ratio for Attack Source Tracing........................................................................ 177
3.5.4 Configuring an Attack Source Tracing Mode.........................................................................................................177
3.5.5 Configuring the Types of Traced Packets................................................................................................................ 178
3.5.6 Configuring a Whitelist for Attack Source Tracing.............................................................................................. 179
3.5.7 Configuring Event Reporting Function.................................................................................................................... 180
Issue 12 (2020-11-15) Copyright © Huawei Technologies Co., Ltd. viii
S1720, S2700, S5700, and S6720 Series Ethernet
Switches
Configuration Guide - Security Contents
3.5.8 Configuring Attack Source Punish Actions............................................................................................................. 181
3.5.9 Applying an Attack Defense Policy........................................................................................................................... 181
3.5.10 Verifying the Attack Source Tracing Configuration...........................................................................................182
3.6 Configuring Port Attack Defense.................................................................................................................................. 182
3.6.1 Creating an Attack Defense Policy............................................................................................................................ 183
3.6.2 Enabling Port Attack Defense..................................................................................................................................... 183
3.6.3 Specifying the Protocols to Which Port Attack Defense Is Applied............................................................... 184
3.6.4 Setting the Rate Threshold for Port Attack Defense.......................................................................................... 184
3.6.5 Setting the Sampling Ratio for Port Attack Defense.......................................................................................... 185
3.6.6 Setting the Aging Time for Port Attack Defense..................................................................................................186
3.6.7 (Optional) Configuring the Whitelist for Port Attack Defense....................................................................... 187
3.6.8 Configuring the Report of Port Attack Defense Events..................................................................................... 187
3.6.9 Applying an Attack Defense Policy........................................................................................................................... 189
3.6.10 Verifying the Port Attack Defense Configuration.............................................................................................. 189
3.7 Configuring the User-Level Rate Limiting.................................................................................................................. 189
3.7.1 Enabling the User-Level Rate Limiting.................................................................................................................... 190
3.7.2 Configuring the User-Level Rate Limit.................................................................................................................... 190
3.7.3 Specifying the Packet Types to Which the User-Level Rate Limiting Applies............................................ 191
3.7.4 Disabling User-Level Rate Limiting on Interface..................................................................................................191
3.7.5 Verifying the User-Level Rate Limiting Configuration....................................................................................... 192
3.8 Maintaining Local Attack Defense............................................................................................................................... 192
3.8.1 Clearing Attack Source Information......................................................................................................................... 192
3.8.2 Clearing Statistics About Packets Sent to the CPU............................................................................................. 193
3.8.3 Clearing History Records on Dynamic Adjustment of Default CIR Values of Protocol Packets.......... 193
3.8.4 Deleting Packet Statistics on Port Attack Defense.............................................................................................. 194
3.8.5 Clearing Packet Statistics in User-Level Rate Limiting....................................................................................... 194
3.9 Example for Configuring Local Attack Defense....................................................................................................... 195
3.10 Example for Configuring Attack Source Tracing....................................................................................................198
3.11 Troubleshooting Local Attack Defense..................................................................................................................... 201
3.11.1 Attack Source Tracing Does Not Take Effect....................................................................................................... 201
3.11.2 Protocol Packets Are Not Sent to the CPU.......................................................................................................... 202
3.11.3 The Blacklist Does Not Take Effect.........................................................................................................................203
3.12 FAQ About Local Attack Defense............................................................................................................................... 203
3.12.1 How Can the CPU Be Protected from DHCPv6 Messages?............................................................................203
3.12.2 What Is the Effect of Excess ARP Reply Packets on the CPU? ..................................................................... 203
3.12.3 How Can I Identify an Attack and How Can I Prevent Attacks?.................................................................. 204
3.13 Attack Defense Packet Types....................................................................................................................................... 204
4 MFF Configuration.............................................................................................................. 228
4.1 Overview of MFF................................................................................................................................................................ 228
4.2 Understanding MFF........................................................................................................................................................... 229
4.3 Application Scenarios for MFF....................................................................................................................................... 232
4.4 Licensing Requirements and Limitations for MFF...................................................................................................233
Issue 12 (2020-11-15) Copyright © Huawei Technologies Co., Ltd. ix
S1720, S2700, S5700, and S6720 Series Ethernet
Switches
Configuration Guide - Security Contents
4.5 Configuring MFF................................................................................................................................................................. 236
4.5.1 Enabling Global MFF..................................................................................................................................................... 236
4.5.2 Configuring a Network Interface...............................................................................................................................237
4.5.3 Enabling MFF in a VLAN.............................................................................................................................................. 237
4.5.4 (Optional) Configuring a Static Gateway Address.............................................................................................. 238
4.5.5 (Optional) Enabling Timed Gateway Address Detection.................................................................................. 238
4.5.6 (Optional) Configuring the Application Server IP Address...............................................................................239
4.5.7 (Optional) Configuring the Switch to Transparently Transmit ARP Request Packets............................. 240
4.5.8 (Optional) Configuring the Switch to Forward the ARP Packets from Gateway to Dumb Terminals
......................................................................................................................................................................................................... 240
4.5.9 (Optional) Discarding IPv6 Packets Sent from Users......................................................................................... 241
4.5.10 (Optional) Configuring MFF to Be Enabled When Receiving ARP Packets.............................................. 242
4.5.11 (Optional) Discarding IGMP Query Messages Sent form Users.................................................................. 242
4.5.12 Verifying the MFF Configuration.............................................................................................................................243
4.6 Configuration Examples for MFF.................................................................................................................................. 243
4.6.1 Example for Configuring MFF to Implement Layer 2 Isolation and Layer 3 Connection...................... 243
4.7 Troubleshooting MFF........................................................................................................................................................ 248
4.7.1 Users Fail to Access the Internet After MFF Is Configured...............................................................................248
4.8 FAQ About MFF...................................................................................................................................................................251
4.8.1 After MFF is Enabled in a VLAN and Timed Gateway Address Detection is Enabled, the Gateway
MAC Address is Empty Although the Switch Has Learned the Gateway MAC Address. Why?...................... 251
4.8.2 Why Do Users with Static IP Addresses Fail to Ping Each Other When the Switch Is Configured with
the MFF Function and a Static Gateway Address?........................................................................................................ 251
4.8.3 ARP Rate Limiting Is Configured and MFF Is Enabled in the VLAN. Does ARP Rate Limiting Place a
Limit on the Rate of Packets Processed by the MFF Module?................................................................................... 252
5 Attack Defense Configuration..........................................................................................253
5.1 Overview of Attack Defense........................................................................................................................................... 253
5.2 Understanding Attack Defense...................................................................................................................................... 254
5.2.1 Defense Against Malformed Packet Attacks......................................................................................................... 254
5.2.2 Defense Against Packet Fragment Attacks............................................................................................................ 255
5.2.3 Defense Against Flood Attacks...................................................................................................................................261
5.3 Application Scenarios for Attack Defense.................................................................................................................. 262
5.4 Licensing Requirements and Limitations for Attack Defense..............................................................................263
5.5 Default Settings for Attack Defense............................................................................................................................ 266
5.6 Configuring Defense Against Malformed Packet Attacks.................................................................................... 266
5.7 Configuring Defense Against Packet Fragment Attacks....................................................................................... 267
5.8 Configuring Defense Against Flood Attacks..............................................................................................................268
5.8.1 Configuring Defense Against TCP SYN Flood Attacks........................................................................................ 268
5.8.2 Configuring Defense Against UDP Flood Attacks................................................................................................ 269
5.8.3 Configuring Defense Against ICMP Flood Attacks.............................................................................................. 269
5.8.4 Verifying the Flood Attack Defense Configuration..............................................................................................270
5.9 Clearing Attack Defense Statistics................................................................................................................................ 270
5.10 Example for Configuring Attack Defense................................................................................................................ 270
Issue 12 (2020-11-15) Copyright © Huawei Technologies Co., Ltd. x
S1720, S2700, S5700, and S6720 Series Ethernet
Switches
Configuration Guide - Security Contents
6 Traffic Suppression and Storm Control Configuration...............................................273
6.1 Overview of Traffic Suppression and Storm Control..............................................................................................273
6.2 Understanding Traffic Suppression.............................................................................................................................. 274
6.3 Understanding Storm Control........................................................................................................................................ 275
6.4 Application Scenarios for Traffic Suppression.......................................................................................................... 275
6.5 Application Scenarios for Storm Control.................................................................................................................... 276
6.6 Licensing Requirements and Limitations for Traffic Suppression and Storm Control................................ 276
6.7 Default Settings for Traffic Suppression and Storm Control............................................................................... 279
6.8 Configuring Traffic Suppression.................................................................................................................................... 280
6.8.1 Configuring Traffic Suppression on an Interface................................................................................................. 280
6.8.2 Configuring Traffic Suppression in a VLAN............................................................................................................282
6.8.3 Configuring Traffic Suppression for ICMP Packets.............................................................................................. 282
6.8.4 Verifying the Traffic Suppression Configuration.................................................................................................. 283
6.9 Configuring Storm Control.............................................................................................................................................. 283
6.10 Configuration Examples for Traffic Suppression and Storm Control............................................................. 285
6.10.1 Example for Configuring Traffic Suppression..................................................................................................... 285
6.10.2 Example for Configuring Storm Control............................................................................................................... 286
6.11 Troubleshooting Traffic Suppression and Storm Control................................................................................... 288
6.11.1 Broadcast Traffic Suppression Does Not Take Effect....................................................................................... 288
7 ARP Security Configuration.............................................................................................. 290
7.1 Overview of ARP Security................................................................................................................................................ 290
7.2 ARP Security Solutions...................................................................................................................................................... 291
7.3 Understanding ARP Security........................................................................................................................................... 300
7.3.1 Rate Limiting on ARP Packets.....................................................................................................................................300
7.3.2 Rate Limiting on ARP Miss Messages...................................................................................................................... 301
7.3.3 Optimized ARP Reply..................................................................................................................................................... 303
7.3.4 Strict ARP Learning......................................................................................................................................................... 305
7.3.5 ARP Entry Limiting.......................................................................................................................................................... 306
7.3.6 Disabling ARP Learning on Interfaces..................................................................................................................... 306
7.3.7 ARP Entry Fixing.............................................................................................................................................................. 306
7.3.8 DAI........................................................................................................................................................................................308
7.3.9 ARP Gateway Anti-Collision........................................................................................................................................ 310
7.3.10 Gratuitous ARP Packet Sending............................................................................................................................... 311
7.3.11 ARP Gateway Protection............................................................................................................................................ 311
7.3.12 MAC Address Consistency Check in an ARP Packet..........................................................................................312
7.3.13 ARP Packet Validity Check......................................................................................................................................... 312
7.3.14 ARP Learning Triggered by DHCP........................................................................................................................... 313
7.3.15 ARP Proxy on a VPLS Network.................................................................................................................................313
7.4 Application Scenarios for ARP Security....................................................................................................................... 313
7.4.1 Defense Against ARP Flood Attacks......................................................................................................................... 313
7.4.2 Defense Against ARP Spoofing Attacks................................................................................................................... 315
7.5 Licensing Requirements and Limitations for ARP Security.................................................................................. 316
Issue 12 (2020-11-15) Copyright © Huawei Technologies Co., Ltd. xi
S1720, S2700, S5700, and S6720 Series Ethernet
Switches
Configuration Guide - Security Contents
7.6 Default Settings for ARP Security................................................................................................................................. 318
7.7 Configuring Defense Against ARP Flood Attacks.................................................................................................... 320
7.7.1 Configuring Rate Limiting on ARP Packets based on Source MAC Addresses...........................................321
7.7.2 Configuring Rate Limiting on ARP Packets based on Source IP Addresses................................................ 322
7.7.3 Configuring Rate Limiting on ARP Packets Globally, in a VLAN, or on an Interface...............................322
7.7.4 Configuring Rate Limiting on ARP Miss Messages based on Source IP Addresses.................................. 324
7.7.5 Configuring Rate Limiting on ARP Miss Messages Globally, in a VLAN, or on an Interface................ 326
7.7.6 Configuring the Aging Time of Temporary ARP Entries.................................................................................... 327
7.7.7 Configuring the Optimized ARP Reply Function.................................................................................................. 328
7.7.8 Configuring Strict ARP Learning................................................................................................................................ 330
7.7.9 Configuring Interface-based ARP Entry Limiting................................................................................................. 331
7.7.10 Disabling an Interface from Learning ARP Entries........................................................................................... 332
7.7.11 Verifying the ARP Flood Attack Defense Configuration.................................................................................. 333
7.8 Configuring Defense Against ARP Spoofing Attacks.............................................................................................. 333
7.8.1 Configuring ARP Entry Fixing......................................................................................................................................334
7.8.2 Configuring DAI............................................................................................................................................................... 335
7.8.3 Configuring ARP Gateway Anti-Collision................................................................................................................ 337
7.8.4 Configuring Gratuitous ARP Packet Sending......................................................................................................... 338
7.8.5 Configuring ARP Gateway Protection...................................................................................................................... 339
7.8.6 Configuring MAC Address Consistency Check in an ARP Packet....................................................................340
7.8.7 Configuring ARP Packet Validity Check................................................................................................................... 341
7.8.8 Configuring Strict ARP Learning................................................................................................................................ 341
7.8.9 Configuring ARP Learning Triggered by DHCP..................................................................................................... 343
7.8.10 Configuring ARP Proxy on a VPLS Network........................................................................................................ 344
7.8.11 Verifying the ARP Spoofing Attack Defense Configuration........................................................................... 344
7.9 Maintaining ARP Security................................................................................................................................................ 345
7.9.1 Monitoring ARP Running Status................................................................................................................................ 345
7.9.2 Clearing ARP Security Statistics................................................................................................................................. 346
7.9.3 Configuring the Alarm Function for Potential ARP Attacks............................................................................. 346
7.10 Configuration Examples for ARP Security............................................................................................................... 347
7.10.1 Example for Configuring ARP Security Functions..............................................................................................347
7.10.2 Example for Configuring Defense Against ARP MITM Attacks.....................................................................351
7.11 FAQ About ARP Security................................................................................................................................................ 354
7.11.1 Why Cannot ARP Entries Be Dynamically Migrated on the Switch?.......................................................... 355
7.11.2 Strict ARP Learning Is Enabled on the Switch, and a User Has Learned the Switch's ARP Entry. Why
Cannot the Switch Learn the User ARP Entry by Pinging the User?........................................................................355
7.11.3 Why Cannot a DAI-enabled Switch Forward Valid ARP Packets at Line Rate?...................................... 355
7.11.4 DAI and EAI Are Enabled on a Switch. Why Can the Switch Forward ARP Packets Sent by
Unauthorized Users to Request MAC Addresses of Authorized Users?.................................................................. 355
7.11.5 DAI Is Enabled on a Switch, and the Source MAC Address of an ARP Packet Is Checked Against the
Source MAC Address in an Ethernet Frame Header. An ARP Packet with its Source MAC Address Different
from that in the Ethernet Frame Header Can Pass the Check. Why?..................................................................... 356
7.11.6 Can the IP Address of a VLANIF Interface in a DAI-enabled VLAN Be Successfully Pinged?............ 356
Issue 12 (2020-11-15) Copyright © Huawei Technologies Co., Ltd. xii
S1720, S2700, S5700, and S6720 Series Ethernet
Switches
Configuration Guide - Security Contents
7.11.7 Why the S2752/S3700 CPU Usage Is Too High When Many VLANIF Interfaces Are Configured on
the S2752/S3700?...................................................................................................................................................................... 356
7.11.8 How Can I Detect Whether ARP Attacks Are Occurring on the Device?...................................................356
7.11.9 Can the Device Be Deployed with the ARP Anti-Attack Function?............................................................. 360
7.11.10 What Is ARP Miss?..................................................................................................................................................... 364
7.11.11 How Can I Handle an ARP Learning Failure Caused by ARP Miss Messages?..................................... 365
7.11.12 How Can ARP Miss Logs and Alarms Be Disabled?....................................................................................... 366
7.11.13 How Can I Prevent ARP Attacks Targeted at Static Users?......................................................................... 367
7.11.14 What Do I Do If the Device Receives a Large Number of ARP Request or Reply Packets?............. 367
7.11.15 Can the Device Prevent ARP Attacks After the ARP Anti-Attack Function Is Configured?...............369
8 Port Security Configuration.............................................................................................. 370
8.1 Overview of Port Security................................................................................................................................................ 370
8.2 Understanding Port Security...........................................................................................................................................370
8.3 Application Scenarios for Port Security.......................................................................................................................373
8.4 Licensing Requirements and Limitations for Port Security.................................................................................. 375
8.5 Default Settings for Port Security................................................................................................................................. 378
8.6 Configuring Port Security................................................................................................................................................ 378
8.6.1 Configuring the Secure MAC Address Function....................................................................................................378
8.6.2 Configuring the Sticky MAC Address Function..................................................................................................... 380
8.7 Configuring the Static MAC Flapping Trap................................................................................................................ 382
8.8 Example for Configuring Port Security....................................................................................................................... 384
8.9 Port Security FAQ............................................................................................................................................................... 386
8.9.1 How Can I Obtain the MACsec Plug-in and Related Documentation?........................................................ 386
9 DHCP Snooping Configuration.........................................................................................387
9.1 Overview of DHCP Snooping......................................................................................................................................... 387
9.2 Understanding DHCP Snooping.................................................................................................................................... 388
9.2.1 DHCP Snooping Fundamentals.................................................................................................................................. 388
9.2.2 Option 82 Supported by DHCP Snooping.............................................................................................................. 390
9.2.3 LDRA Supported by DHCPv6 Snooping................................................................................................................... 392
9.2.4 Option 18 and Option 37 Fields Supported by DHCPv6 Snooping............................................................... 393
9.3 Application Scenarios for DHCP Snooping................................................................................................................ 393
9.3.1 Defense Against Bogus DHCP Server Attacks....................................................................................................... 393
9.3.2 Defense Against Attacks from Non-DHCP Users................................................................................................. 394
9.3.3 Defense Against DHCP Flood Attacks......................................................................................................................395
9.3.4 Defense Against Bogus DHCP Message Attacks.................................................................................................. 395
9.3.5 Defense Against DHCP Server DoS Attacks........................................................................................................... 395
9.3.6 Typical Application of the Option 82 Field.............................................................................................................396
9.3.7 Detecting Client Locations Through an LDRA...................................................................................................... 397
9.4 Licensing Requirements and Limitations for DHCP Snooping............................................................................ 398
9.5 Default Settings for DHCP Snooping........................................................................................................................... 401
9.6 Configuring Basic Functions of DHCP Snooping..................................................................................................... 402
9.6.1 Enabling DHCP Snooping............................................................................................................................................. 402
Issue 12 (2020-11-15) Copyright © Huawei Technologies Co., Ltd. xiii
S1720, S2700, S5700, and S6720 Series Ethernet
Switches
Configuration Guide - Security Contents
9.6.2 Configuring an Interface as a Trusted Interface...................................................................................................404
9.6.3 (Optional) Disabling Location Transition for DHCP Snooping Users............................................................405
9.6.4 (Optional) Configuring Association Between ARP and DHCP Snooping.....................................................406
9.6.5 (Optional) Configuring the Device to Clear the MAC Address Entry As Soon As a User Is
Disconnected............................................................................................................................................................................... 406
9.6.6 (Optional) Configuring the Device to Discard DHCP Request Messages When GIADDR Field Is Not 0
......................................................................................................................................................................................................... 407
9.6.7 Verifying the DHCP Snooping Configuration........................................................................................................ 409
9.7 Configuring DHCP Snooping Attack Mitigation...................................................................................................... 409
9.7.1 Enabling DHCP Server Detection ............................................................................................................................ 410
9.7.2 Configuring Defense Against DHCP Flood Attacks............................................................................................. 410
9.7.3 Configuring Defense Against Bogus DHCP Message Attacks..........................................................................413
9.7.4 Configuring Defense Against DHCP Server DoS Attacks...................................................................................415
9.7.5 Verifying the DHCP Snooping Attack Defense Configuration......................................................................... 418
9.8 Inserting the Option 82 Field in a DHCP Message................................................................................................. 418
9.9 Configuring the LDRA to Detect Client Locations...................................................................................................422
9.10 Inserting the Option 18 or Option 37 Field in a DHCPv6 Message............................................................... 423
9.11 Maintaining DHCP Snooping....................................................................................................................................... 425
9.11.1 Clearing DHCP Snooping Statistics.........................................................................................................................426
9.11.2 Clearing DHCP Snooping Binding Entries............................................................................................................ 426
9.11.3 Backing Up DHCP Snooping Binding Entries...................................................................................................... 427
9.11.4 Restoring DHCP Snooping Binding Entries.......................................................................................................... 428
9.12 Configuration Examples for DHCP Snooping......................................................................................................... 428
9.12.1 Example for Configuring DHCP Snooping Attack Defense............................................................................ 428
9.12.2 Example for Configuring DHCP Snooping on a VPLS Network....................................................................434
9.12.3 Example for Configuring LDRA to Detect Client Locations............................................................................438
9.13 Troubleshooting DHCP Snooping............................................................................................................................... 441
9.13.1 Some Users Cannot Obtain IP Addresses after DHCP Snooping Is Enabled............................................441
9.13.2 All Users Cannot Obtain IP Address after DHCP Snooping Is Enabled......................................................442
9.14 FAQ....................................................................................................................................................................................... 443
9.14.1 Which Devices Support DHCP Snooping?............................................................................................................ 443
9.14.2 Why Can't Users Obtain IP Addresses after DHCP Snooping Is Configured?.......................................... 443
9.14.3 Why Can't a PC Access the Internet after Obtaining an IP Address Through DHCP............................ 443
10 ND Snooping Configuration........................................................................................... 444
10.1 Overview of ND Snooping............................................................................................................................................ 444
10.2 Understanding ND Snooping....................................................................................................................................... 445
10.3 Application Scenarios for ND Snooping................................................................................................................... 447
10.3.1 Address Spoofing Attack Defense........................................................................................................................... 447
10.3.2 RA Attack Defense........................................................................................................................................................ 448
10.4 Licensing Requirements and Limitations for ND Snooping...............................................................................450
10.5 Default Settings for ND Snooping............................................................................................................................. 452
10.6 Configuring ND Snooping............................................................................................................................................. 453
10.6.1 Enabling ND snooping................................................................................................................................................ 453
Issue 12 (2020-11-15) Copyright © Huawei Technologies Co., Ltd. xiv
S1720, S2700, S5700, and S6720 Series Ethernet
Switches
Configuration Guide - Security Contents
10.6.2 Configuring an ND snooping Trusted Interface................................................................................................. 455
10.6.3 Configuring ND Protocol Packet Validity Check................................................................................................ 456
10.6.4 (Optional) Enabling Automatic User Status Detection for Users Mapping ND Snooping Dynamic
Binding Entries............................................................................................................................................................................ 458
10.6.5 (Optional) Setting the Maximum Number of ND Snooping Dynamic Binding Entries to Be Learned
by an Interface............................................................................................................................................................................ 459
10.6.6 (Optional) Configuring Alarm Thresholds for the Percentage of ND Snooping Dynamic Binding
Entries............................................................................................................................................................................................ 460
10.6.7 Verifying the ND Snooping Configuration........................................................................................................... 460
10.7 Maintaining ND Snooping............................................................................................................................................ 461
10.7.1 Clearing the Prefix Management Table................................................................................................................ 461
10.7.2 Clearing the ND Snooping Dynamic Binding Table..........................................................................................461
10.7.3 Clearing ND Snooping Statistics..............................................................................................................................462
10.8 Configuration Examples for ND Snooping.............................................................................................................. 462
10.8.1 Example for Configuring ND Snooping................................................................................................................ 462
11 PPPoE+ Configuration...................................................................................................... 467
11.1 Overview of PPPoE+........................................................................................................................................................ 467
11.2 Licensing Requirements and Limitations for PPPoE+.......................................................................................... 469
11.3 Default Settings for PPPoE+......................................................................................................................................... 472
11.4 Configuring PPPoE+........................................................................................................................................................ 472
11.4.1 Enabling the PPPoE+ Function................................................................................................................................. 472
11.4.2 Configuring the PPPoE Trusted Interface............................................................................................................. 473
11.4.3 Configuring the Policy for Processing User-Side PPPoE Packets.................................................................. 473
11.4.4 (Optional) Configuring a Policy for Processing PPPoE Packets Sent by the PPPoE Server.................475
11.4.5 Verifying the PPPoE+ Configuration...................................................................................................................... 476
11.5 Configuration Examples for PPPoE+..........................................................................................................................476
11.5.1 Example for Configuring PPPoE+............................................................................................................................ 476
11.6 Troubleshooting PPPoE+................................................................................................................................................ 478
11.6.1 PPPoE Users Cannot Go Online............................................................................................................................... 478
12 IPSG Configuration........................................................................................................... 480
12.1 Overview of IPSG............................................................................................................................................................. 480
12.2 Understanding IPSG........................................................................................................................................................ 481
12.2.1 IPSG Fundamentals...................................................................................................................................................... 481
12.2.2 IPSG Deployment.......................................................................................................................................................... 485
12.2.3 Comparison Between IPSG and Other Features................................................................................................ 486
12.3 Application Scenarios for IPSG.................................................................................................................................... 491
12.4 Summary of IPSG Configuration Tasks.....................................................................................................................492
12.5 Licensing Requirements and Limitations for IPSG................................................................................................ 494
12.6 Default Settings for IPSG...............................................................................................................................................497
12.7 Configuring IPSG.............................................................................................................................................................. 497
12.7.1 Configuring IPSG Based on a Static Binding Table........................................................................................... 497
12.7.2 Configuring IPSG Based on a Dynamic Binding Table.....................................................................................501
Issue 12 (2020-11-15) Copyright © Huawei Technologies Co., Ltd. xv
S1720, S2700, S5700, and S6720 Series Ethernet
Switches
Configuration Guide - Security Contents
12.7.3 Configuring the Generation of Snooping MAC Entries Based on the Binding Table............................ 505
12.7.4 Discarding IP Packets with Identical Source and Destination IP Addresses............................................. 507
12.8 Maintaining IPSG............................................................................................................................................................. 508
12.9 Configuration Examples for IPSG............................................................................................................................... 508
12.9.1 Example for Configuring IPSG Based on the Static Binding Table to Prevent Hosts from Changing
Their Own IP Addresses........................................................................................................................................................... 508
12.9.2 Example for Configuring IPSG Based on the DHCP Snooping Dynamic Binding Table to Prevent
Hosts from Changing Their Own IP Addresses............................................................................................................... 510
12.9.3 Example for Configuring IPSG Based on the Static Binding Table to Prevent Unauthorized Hosts
from Accessing the intranet................................................................................................................................................... 513
12.10 Troubleshooting IPSG................................................................................................................................................... 516
12.10.1 IPSG Does Not Take Effect Because IPSG Is Not Enabled on the Interface or VLAN......................... 516
12.10.2 An Authorized Host Cannot Go Online Due to the Incorrect Static Binding Entry.............................517
12.10.3 Service Is Abnormal Because the Upstream Interface Is Not Configured as a Trusted Interface.. 518
12.10.4 Service Is Interrupted After IPSG Is Enabled on the Upstream Interface............................................... 519
12.10.5 Unbound Hosts Can Go Online After IP and MAC Bindings Are Configured........................................520
12.10.6 IPSG Does Not Take Effect When Dynamic IP Address Allocation Is Used Because DHCP Snooping
Is Not Configured...................................................................................................................................................................... 521
12.11 FAQ About IPSG............................................................................................................................................................. 522
12.11.1 Does a Switch Support the Binding of One Interface and Multiple IP Addresses............................... 522
12.11.2 Does a Switch Support the Binding of One MAC Address and Multiple IP Addresses...................... 522
13 SAVI Configuration........................................................................................................... 523
13.1 Overview of SAVI............................................................................................................................................................. 523
13.2 Licensing Requirements and Limitations for SAVI................................................................................................523
13.3 Default Settings for SAVI...............................................................................................................................................526
13.4 Configuring the SAVI Function.................................................................................................................................... 526
13.4.1 Enabling SAVI................................................................................................................................................................. 527
13.4.2 (Optional) Setting the Maximum Number of SAVI Binding Entries on an Interface........................... 527
13.4.3 (Optional) Setting the Time for Listing to an NA Packet in Response to Duplicate Addresses........528
13.4.4 (Optional) Setting the Time for Listening to the Duplicate Address Detection Performed by the
DHCPv6 Client............................................................................................................................................................................ 529
13.4.5 Verifying the SAVI Configuration............................................................................................................................ 530
13.5 Configuration Examples for SAVI............................................................................................................................... 530
13.5.1 Example for Configuring the SAVI Function in a DHCPv6-Only Scenario................................................ 530
13.5.2 Example for Configuring the SAVI Function in an SLAAC-Only Scenario................................................. 533
13.5.3 Example for Configuring the SAVI Function in a DHCPv6+SLAAC Scenario............................................536
14 URPF Configuration.......................................................................................................... 541
14.1 Overview of URPF............................................................................................................................................................ 541
14.2 Understanding URPF....................................................................................................................................................... 542
14.3 Application Scenarios for URPF................................................................................................................................... 543
14.4 Licensing Requirements and Limitations for URPF.............................................................................................. 545
14.5 Default Settings for URPF............................................................................................................................................. 548
14.6 Configuring URPF Check................................................................................................................................................548
Issue 12 (2020-11-15) Copyright © Huawei Technologies Co., Ltd. xvi
S1720, S2700, S5700, and S6720 Series Ethernet
Switches
Configuration Guide - Security Contents
14.7 Example for Configuring URPF....................................................................................................................................551
15 Keychain Configuration................................................................................................... 556
15.1 Overview of Keychains................................................................................................................................................... 556
15.2 Understanding Keychains.............................................................................................................................................. 557
15.2.1 Basic Concepts of Keychains..................................................................................................................................... 557
15.2.2 Implementation of Keychains for a Non-TCP Application.............................................................................. 559
15.2.3 Implementation of Keychains for TCP Applications......................................................................................... 561
15.3 Application Scenarios for Keychains.......................................................................................................................... 563
15.4 Licensing Requirements and Limitations for Keychain....................................................................................... 564
15.5 Configuring a Keychain.................................................................................................................................................. 566
15.5.1 Creating a Keychain..................................................................................................................................................... 566
15.5.2 Configuring a Key......................................................................................................................................................... 567
15.5.3 Applying the Keychain................................................................................................................................................ 569
15.5.4 Verifying the Keychain Configuration....................................................................................................................570
15.6 Configuration Examples for Keychains..................................................................................................................... 570
15.6.1 Example for Applying the Keychain to RIP.......................................................................................................... 571
15.6.2 Example for Applying the Keychain to BGP........................................................................................................ 574
16 MPAC Configuration.........................................................................................................579
16.1 Overview of MPAC........................................................................................................................................................... 579
16.2 Understanding MPAC..................................................................................................................................................... 580
16.3 Licensing Requirements and Limitations for MPAC............................................................................................. 581
16.4 Configuring MPAC........................................................................................................................................................... 583
16.4.1 Configuring IPv4 MPAC Policy..................................................................................................................................583
16.4.2 Configuring IPv6 MPAC Policy..................................................................................................................................586
16.4.3 Verifying the MPAC Configuration......................................................................................................................... 588
16.5 Clearing MPAC Statistics................................................................................................................................................588
16.6 Example for Configuring MPAC.................................................................................................................................. 589
17 PKI Configuration..............................................................................................................591
17.1 Overview of PKI................................................................................................................................................................ 592
17.2 Understanding PKI........................................................................................................................................................... 592
17.2.1 Basic Concepts of PKI.................................................................................................................................................. 592
[Link] Cryptography.............................................................................................................................................................. 593
[Link] Digital Envelope and Digital Signature............................................................................................................. 595
[Link] Digital Certificate...................................................................................................................................................... 598
17.2.2 PKI System Structure................................................................................................................................................... 601
17.2.3 PKI Working Mechanism............................................................................................................................................ 604
17.3 Application Scenarios for PKI....................................................................................................................................... 606
17.3.1 Application in SSH........................................................................................................................................................ 606
17.4 Licensing Requirements and Limitations for PKI...................................................................................................607
17.5 Default Settings for PKI................................................................................................................................................. 610
17.6 Summary of PKI Configuration Tasks....................................................................................................................... 610
Issue 12 (2020-11-15) Copyright © Huawei Technologies Co., Ltd. xvii
S1720, S2700, S5700, and S6720 Series Ethernet
Switches
Configuration Guide - Security Contents
17.7 Preconfiguring a Local Certificate.............................................................................................................................. 613
17.7.1 Configuring a PKI Entity............................................................................................................................................. 613
17.7.2 Configuring an RSA Key Pair.................................................................................................................................... 614
17.7.3 Configuring a PKI Entity to Obtain a CA Certificate.........................................................................................616
[Link] Downloading a CA Certificate for a PKI Entity............................................................................................... 616
[Link] (Optional) Installing a CA Certificate for a PKI Entity................................................................................. 617
17.7.4 Verifying the Local Certificate Preconfiguration................................................................................................ 618
17.8 Applying for and Updating Local Certificate.......................................................................................................... 618
17.8.1 Applying for and Updating the Local Certificate Through SCEP..................................................................618
17.8.2 Applying for the Local Certificate in Offline Mode...........................................................................................622
17.8.3 Verifying the Local Certificate Application and Update Configuration..................................................... 623
17.9 (Optional) Downloading a Local Certificate.......................................................................................................... 624
17.10 (Optional) Installing the Local Certificate............................................................................................................ 625
17.11 Verifying the CA and Local Certificates................................................................................................................. 626
17.11.1 Configuring Local Certificate Check.....................................................................................................................626
17.11.2 Checking the CA and Local Certificates ............................................................................................................ 630
17.11.3 Verifying the CA and Local Certificate Configuration................................................................................... 631
17.12 Deleting the Local Certificate.................................................................................................................................... 632
17.13 Configuring the Extended Functions ..................................................................................................................... 632
17.13.1 Configuring Certificate Obtaining........................................................................................................................ 632
17.13.2 Importing and Releasing a Peer Certificate...................................................................................................... 633
17.13.3 Configuring a Self-Signed Certificate.................................................................................................................. 634
17.13.4 Adding a PKI to a Specified VPN.......................................................................................................................... 634
17.14 Maintaining PKI.............................................................................................................................................................. 635
17.14.1 Checking PKI Information....................................................................................................................................... 635
17.15 Configuration Examples for PKI................................................................................................................................635
17.15.1 Example for Configuring Automatic Local Certificate Application Using SCEP....................................635
17.15.2 Example for Applying for the Local Certificate in Offline Mode............................................................... 641
17.16 Troubleshooting PKI...................................................................................................................................................... 645
17.16.1 A CA Certificate Failed to Be Obtained.............................................................................................................. 645
17.16.2 A Local Certificate Failed to Be Obtained..........................................................................................................646
17.17 FAQ About PKI................................................................................................................................................................ 648
17.17.1 What Are the Differences Between CA, Local, and Self-Signed Certificates?....................................... 648
18 Separating the Management Plane from the Service Plane.................................. 650
19 Checking Security Risks................................................................................................... 652
Issue 12 (2020-11-15) Copyright © Huawei Technologies Co., Ltd. xviii