Configuring Dynamic Arp Inspection; Dai Configuration; Figure 130: Dynamic Arp Inspection Configuration - D-Link DWS-4026 User Manual

Dws-4000 series unified wired & wireless access system
Table of Contents

Advertisement

D-Link Unified Access System
Field
GARP Leave All Timer
(centisecs)
If you make any changes to the page, click Submit to apply the changes to the system.
C
D
ONFIGURING
Dynamic ARP Inspection (DAI) is a security feature that rejects invalid and malicious ARP packets. DAI prevents a class of
man-in-the-middle attacks, where an unfriendly station intercepts traffic for other stations by poisoning the ARP caches of
its unsuspecting neighbors. The miscreant sends ARP requests or responses mapping another station's IP address to its
own MAC address.
DAI relies on DHCP snooping. DHCP snooping listens to DHCP message exchanges and builds a binding database of valid
{MAC address, IP address, VLAN, and interface} tuples.
When DAI is enabled, the switch drops ARP packets whose sender MAC address and sender IP address do not match an
entry in the DHCP snooping bindings database. You can optionally configure additional ARP packet validation.
DAI C
ONFIGURATION
Use the DAI Configuration page to configure global DAI settings.
To display the DAI Configuration page, click LAN > L2 Features > Dynamic ARP Inspection > DAI Configuration in the
navigation tree.
Page 208

Configuring Dynamic ARP Inspection

Table 112: GARP Port Configuration Fields (Cont.)
Description
Displays time lapse, in centiseconds, that all switches wait before leaving the GARP
state. The leave all time must be greater than the leave time. The possible field value
is 200-6000. The default value is 1000 centisecs. The Leave All Time controls how
frequently LeaveAll PDUs are generated. A LeaveAll PDU indicates that all
registrations will shortly be deregistered. Participants will need to rejoin in order to
maintain registration. The Leave All Period Timer is set to a random value in the range
of LeaveAllTime to 1.5*LeaveAllTime. The timer is specified in centiseconds. Enter a
number between 200 and 6000 (2 to 60 seconds). The factory default is 1000
centiseconds (10 seconds). An instance of this timer exists for each GARP participant
for each port.
ARP I
YNAMIC
NSPECTION

Figure 130: Dynamic ARP Inspection Configuration

Software User Manual
Document 34CSFP6XXUWS-SWUM100-D7
12/10/09

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Dwl-8600apDws-4000 series

Table of Contents