Configuring Arp Gateway Protection; Introduction; Configuration Procedure - H3C S5500-SI Series Operation Manual

Hide thumbs Also See for S5500-SI Series:
Table of Contents

Advertisement

To do...
Enter system view
Enter interface view
Enable ARP automatic
scanning
Return to system view
Enable fixed ARP
IP addresses already existent in ARP entries are not scanned.
ARP automatic scanning may take some time. To stop an ongoing scan, press Ctrl + C. Dynamic
ARP entries are created based on ARP replies received before the scan is terminated.
Fixed ARP changes dynamic ARP entries into static only when these entries are learnt on a Layer
3 Ethernet interface, Layer 3 Ethernet subinterface, or VLAN interface.
The static ARP entries changed from dynamic ARP entries have the same attributes as the static
ARP entries manually configured. Use the arp fixup command to change the recently created
dynamic ARP entries into static.
The number of static ARP entries changed from dynamic ARP entries is restricted by the number
of static ARP entries that the device supports. As a result, the device may fail to change all
dynamic ARP entries into static.
To delete a specific static ARP entry changed from a dynamic one, use the undo arp ip-address
[ vpn-instance-name ] command. To delete all such static ARP entries, use the reset arp all or
reset arp static command.

Configuring ARP Gateway Protection

Introduction

The ARP gateway protection feature, if configured on ports not connected with the gateway, can block
gateway spoofing attacks as follows:
When such a port receives an ARP packet, it checks whether the sender IP address in the packet is
consistent with that of any protected gateway. If yes, it discards the packet. If not, it handles the packets
normally.

Configuration Procedure

Follow these steps to configure ARP gateway protection:
To do...
Enter system view
Enter Layer 2 Ethernet interface
view
Use the command...
system-view
interface interface-type interface-number
arp scan [ start-ip-address to end-ip-address ]
quit
arp fixup
Use the command...
system-view
interface interface-type
interface-number
1-12
Remarks
Required
Optional
Remarks

Advertisement

Chapters

Table of Contents
loading

Table of Contents