Displaying And Maintaining Source Mac Address Based Arp Attack Detection; Configuring Arp Packet Source Mac Address Consistency Check; Introduction; Configuration Procedure - H3C S5500-SI Series Operation Manual

Hide thumbs Also See for S5500-SI Series:
Table of Contents

Advertisement

Displaying and Maintaining Source MAC Address Based ARP Attack Detection

To do...
Display attacking entries
detected

Configuring ARP Packet Source MAC Address Consistency Check

Introduction

This feature enables a gateway device to filter out ARP packets with the source MAC address in the
Ethernet header different from the sender MAC address in the ARP message, so that the gateway
device can learn correct ARP entries.

Configuration Procedure

Follow these steps to enable ARP packet source MAC address consistency check:
To do...
Enter system view
Enable ARP packet source MAC
address consistency check

Configuring ARP Active Acknowledgement

Introduction
Typically, the ARP active acknowledgement feature is configured on gateway devices to identify invalid
ARP packets.
ARP active acknowledgement works before the gateway creates or modifies an ARP entry to avoid
generating any incorrect ARP entry. For details about its working mechanism, refer to ARP Attack
Protection Technology White Paper.
Configuration Procedure
Follow these steps to configure ARP active acknowledgement:
To do...
Enter system view
Enable the ARP active
acknowledgement function
Use the command...
display arp anti-attack source-mac
[ interface interface-type interface-number ]
Use the command...
system-view
arp anti-attack valid-check
enable
Use the command...
system-view
arp anti-attack active-ack
enable
1-5
Remarks
Available in any
view
Remarks
Required
Disabled by default.
Remarks
Required
Disabled by default.

Advertisement

Chapters

Table of Contents
loading

Table of Contents