Arp Inspection Properties - Alcatel OS-LS-6224 User Manual

User guide
Hide thumbs Also See for OS-LS-6224:
Table of Contents

Advertisement

3
Configuring the Switch
• Destination MAC — Compares the packet's destination MAC address in the
Ethernet header against the destination interface's MAC address. This check is
performed for ARP responses.
• IP Addresses — Compares the ARP body for invalid and unexpected IP
addresses. Addresses include 0.0.0.0, 255.255.255.255, and all IP Multicast
addresses.
If the packet's IP address was not found in the ARP Inspection List, and DHCP
snooping is enabled for a VLAN, a search of the DHCP Snooping Database is
performed. If the IP address is found the packet is valid, and is forwarded. ARP
inspection is performed only on untrusted interfaces

ARP Inspection Properties

The ARP Inspection Properties Page provides parameters for enabling and setting
global Dynamic ARP Inspection parameters, as well as defining ARP Inspection Log
parameters.
Command Attributes
• ARP Inspection Status — Indicates if ARP Inspection is enabled on the device.
The possible field values are:
• Enable — Enables ARP Inspection on the device.
• Disable — Disables ARP Inspection on the device. This is the default value.
• ARP Inspection Validate — Indicates that ARP Inspection Validation is enabled
on the device. The possible field values are:
• Enabled — Enables ARP Inspection Validation on the device. If ARP Inspection
Validation is enabled, the following parameters are checked in ARP requests
and responses:
- Source MAC — Validates the source MAC address against the sender's
MAC address in both ARP requests and responses.
- Destination MAC — Validates the destination MAC address against the
recipient's MAC in ARP responses.
- IP addresses — Validates invalid and unexpected IP addresses, including
0.0.0.0, 255.255.255.255, and all IP Multicast addresses.
• Disable — Disable ARP Inspection Validation on the device. This is the default
value.
• Log Buffer Interval — Defines the minimal interval between successive Syslog
messages. The possible field values are:
• Retry Frequency — Frequency at which the log is updated.
• Never — Log is never updated.
Web – Click Security, DHCP Snooping, ARP Inspection, Properties. Define the fields
and click Apply.
178

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents