Configuring Arp Packet Source Mac Consistency Check; Configuring Arp Active Acknowledgement; Configuring Authorized Arp - HP MSR2000 Configuration Manual

Hide thumbs Also See for MSR2000:
Table of Contents

Advertisement

# Set the threshold to 30.
[Device] arp source-mac threshold 30
# Set the lifetime for ARP attack entries to 60 seconds.
[Device] arp source-mac aging-time 60
# Exclude MAC address 0012-3f86-e94c from this detection.
[Device] arp source-mac exclude-mac 0012-3f86-e94c
Configuring ARP packet source MAC consistency
check
This feature enables a gateway to filter out ARP packets whose source MAC address in the Ethernet
header is different from the sender MAC address in the message body, so that the gateway can learn
correct ARP entries.
To enable ARP packet source MAC address consistency check:
Step
1.
Enter system view.
2.
Enable ARP packet source MAC address
consistency check.

Configuring ARP active acknowledgement

Configure this feature on gateways to prevent user spoofing.
ARP active acknowledgement prevents a gateway from generating incorrect ARP entries. For more
information about its working mechanism, see ARP Attack Protection Technology White Paper.
In strict mode, a gateway can learn an entry only when ARP active acknowledgement is performed
based on the correct ARP resolution.
To configure ARP active acknowledgement:
Step
1.
Enter system view.
2.
Enable the ARP active
acknowledgement function.

Configuring authorized ARP

Authorized ARP entries are generated based on the DHCP clients' address leases on the DHCP server or
dynamic client entries on the DHCP relay agent. For more information about DHCP server and DHCP
relay agent, see Layer 3—IP Services Configuration Guide.
Command
system-view
arp valid-check enable
Command
system-view
arp active-ack [ strict ]
enable
278
Remarks
N/A
By default, ARP packet source
MAC address consistency check
is disabled.
Remarks
N/A
By default, ARP active acknowledgement
function is disabled.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Msr3000Msr4000

Table of Contents