Configuring Arp Detection Based On Specified Objects - 3Com 4510G Configuration Manual

3com switch 4510g family
Table of Contents

Advertisement

During the DHCP assignment process, when the client receives the DHCP-ACK message from the
DHCP server, it broadcasts a gratuitous ARP packet to detect address conflicts. If no response is
received in a pre-defined time period, the client uses the assigned IP address. If the client is enabled
with ARP detection based on 802.1X security entries, the IP address is not uploaded to the 802.1X
device before the client uses the IP address. As a result, the gratuitous ARP packet is considered to be
an attack packet and is discarded, and thus cannot detect conflicts. After the client uploads its IP
address to the 802.1X device, subsequent ARP packets sent by the client are considered to be valid
and are allowed to travel through.

Configuring ARP Detection Based on Specified Objects

You can also specify objects in ARP packets to be detected. The objects involve:
src-mac: Checks whether the sender MAC address of an ARP packet is identical to the source
MAC address in the Ethernet header. If they are identical, the packet is forwarded; otherwise, the
packet is discarded.
dst-mac: Checks the target MAC address of ARP replies. If the target MAC address is all-zero,
all-one, or inconsistent with the destination MAC address in the Ethernet header, the packet is
considered invalid and discarded.
ip: Checks both the source and destination IP addresses in an ARP packet. The all-zero, all-one
or multicast IP addresses are considered invalid and the corresponding packets are discarded.
With this object specified, the source and destination IP addresses of ARP replies, and the source
IP address of ARP requests are checked.
Before performing the following configuration, make sure you have configured the arp detection
enable command.
Follow these steps to configure ARP detection based on specified objects:
To do...
Enter system view
Specify objects for ARP detection
Use the command...
system-view
arp detection validate { dst-mac
| ip | src-mac } *
4-8
Remarks
Required
Not specified by default.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents