Configuring Authorized Arp; Introduction; Configuration Procedure; Authorized Arp Configuration Example (On A Dhcp Server) - HP 12500 Series Configuration Manual

Routing
Table of Contents

Advertisement

Configuring authorized ARP

This feature is only supported on Ethernet interfaces that are operating in Layer 3 mode. For more
information about the operating mode of Ethernet interfaces, see Interface Configuration Guide.

Introduction

Authorized ARP entries are generated based on the DHCP clients' address leases on the DHCP server or
dynamic bindings on the DHCP relay agent. For more information about the DHCP server and DHCP
relay agent, see Layer 3—IP Services Configuration Guide.
After enabled with authorized ARP, the interface is disabled from learning dynamic ARP entries to
prevent attacks from unauthorized clients that send packets using other clients' IP or MAC addresses, and
to allow only authorized clients to access network resources. Thus network security is enhanced.
Static ARP entries can overwrite authorized ARP entries, and authorized ARP entries can overwrite
dynamic ARP entries. But authorized ARP entries cannot overwrite static ARP entries, and dynamic ARP
entries cannot overwrite authorized ARP entries.

Configuration procedure

To enable authorized ARP:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Configure the Ethernet interface
to operate in Layer 3 mode.
4.
Configure the DHCP server (or
DHCP relay agent) to support
authorized ARP.
5.
Enable authorized ARP on the
interface.
NOTE:
With the arp authorized enable command executed, an interface of a DHCP server (or a DHCP relay
agent) that does not support authorized ARP is disabled from dynamically learning ARP entries and
cannot generate authorized ARP entries.

Authorized ARP configuration example (on a DHCP server)

IMPORTANT:
By default, Ethernet, VLAN, and aggregate interfaces are down. To configure such an interface, bring the
interface up by executing the undo shutdown command.
Command
system-view
interface interface-type
interface-number
port link-mode route
dhcp update arp
arp authorized enable
270
Remarks
N/A
N/A
For more information about the
operating mode of Ethernet
interfaces, see Interface
Configuration Guide.
Not configured by default.
Not enabled by default.

Advertisement

Table of Contents
loading

Table of Contents