Displaying And Maintaining Arp Detection; Arp Detection Configuration Example - H3C LS-3100-52P-OVS-H3 Operation Manual

S5500-ei series ethernet switches
Table of Contents

Advertisement

dst-mac: Checks the target MAC address of ARP replies. If the target MAC address is all-zero,
all-one, or inconsistent with the destination MAC address in the Ethernet header, the packet is
considered invalid and discarded.
ip: Checks both the source and destination IP addresses in an ARP packet. The all-zero, all-one or
multicast IP addresses are considered invalid and the corresponding packets are discarded. With
this object specified, the source and destination IP addresses of ARP replies, and the source IP
address of ARP requests are checked.
Before performing the following configuration, make sure you have configured the arp detection
enable command.
Follow these steps to configure ARP detection based on specified objects:
To do...
Enter system view
Specify objects for ARP detection
If both the ARP detection based on specified objects and the ARP detection based on snooping
entries/802.1X security entries/static IP-to-MAC bindings are enabled, the former one applies first,
and then the latter applies.
Before enabling ARP detection based on DHCP snooping entries, make sure that DHCP snooping
is enabled.
Before enabling ARP detection based on 802.1X security entries, make sure that 802.1X is
enabled and the 802.1X clients are configured to upload IP addresses.

Displaying and Maintaining ARP Detection

To do...
Display the VLANs enabled
with ARP detection
Display the ARP detection
statistics
Clear the ARP detection
statistics
ARP Detection Configuration Example I
Network requirements
Configure Switch A as a DHCP server and enable DHCP snooping on Switch B. Enable ARP
detection for VLAN 10 to allow only packets from valid clients to pass.
Configure Host A and Host B as DHCP clients.
Use the command...
system-view
arp detection validate { dst-mac
| ip | src-mac } *
Use the command...
display arp detection
display arp detection statistics [ interface
interface-type interface-number ]
reset arp detection statistics [ interface
interface-type interface-number ]
3-8
Remarks
Required
Not specified by default.
Remarks
Available in any view
Available in any view
Available in user view

Advertisement

Chapters

Table of Contents
loading

Table of Contents