Interface Trust Status And Network Security; Restricting Rate Of Arp Packets; Configuring Dai - D-Link xStack DGS-3610 Series Configuration Manual

Hide thumbs Also See for xStack DGS-3610 Series:
Table of Contents

Advertisement

DGS-3610 Series Configuration Guide
43.1.4
Interface Trust Status and Network
Security
ARP packets are checked according to the trust status of each port on the device. DAI check
is ignored for the packets that are received through trusted ports and are considered as legal
ARP packets. DAI check will be performed strictly for the ARP packets that are received
through untrusted ports.
In a typical network configuration, the layer 2 port connected to the network device need be
set as a trusted port, and the layer 2 port connected to the host device need be set as an
untrusted port.
Note: Incorrectly configuring a layer 2 port as an untrusted port may affect normal
communication of the network.
For specific configuration commands, refer to ip arp inspection trust, show ip arp inspection
interface.
43.1.5

Restricting Rate of ARP Packets

Because DAI validity check consumes certain CPU resources, the rate of ARP packets is
restricted, that is, the number of ARP packets received per second is restricted. This
effectively prevents the denial of service attack against the DAI function. By default, the
maximum number of ARP packets received through an untrusted port is 15. This restriction
does not apply to the trusted port. To configure this rate restriction, use the ip arp
inspection limit-rate command in the layer 2 interface configuration mode.
For specific configuration commands, refer to ip arp inspection limit-rate show ip arp
inspection interface

43.2 Configuring DAI

DAI is an ARP-based security filtering technology. A series o f filtering policies are
configured, so that validity of ARP packets that pass the device is checked more effectively.
To use the functions of DAI, selectively perform the following tasks:
Enabling the global DAI function (required)
Enabling the DAI packet check function for specified VLAN (required)
Setting the trust status of ports (optional)
Setting the maximum receiving rate of ARP packets for a port (optional)
Related configuration of DHCP snooping database (optional)
Chapter 43 Dynamic ARP Inspection Configuration
43-3

Advertisement

Table of Contents
loading

Table of Contents