Arp Gateway Protection Configuration Example - H3C S5500-SI Series Operation Manual

Hide thumbs Also See for S5500-SI Series:
Table of Contents

Advertisement

To do...
Enable ARP gateway protection
for a specified gateway
You can enable ARP gateway protection for up to eight gateways on a port.
Commands arp filter source and arp filter binding cannot be both configured on a port.
If ARP gateway protection works with ARP detection, MFF, and ARP snooping, ARP gateway
protection applies first.

ARP Gateway Protection Configuration Example

Network requirements
As shown in
Figure
Switch B intends to send to Switch A is sent to Host B.
It is required to make proper configuration on Switch B to block such attacks.
Figure 1-3 Network diagram for ARP gateway protection configuration
Switch A
Switch B
GE1/0/1
Host A
Configuration procedure
# Configure ARP gateway protection on Switch B.
<SwitchB> system-view
[SwitchB] interface GigabitEthernet 1/0/1
[SwitchB-GigabitEthernet1/0/1] arp filter source 10.1.1.1
[SwitchB-GigabitEthernet1/0/1] quit
[SwitchB] interface GigabitEthernet 1/0/2
[SwitchB-GigabitEthernet1/0/2] arp filter source 10.1.1.1
arp filter source ip-address
1-3, Host B launches gateway spoofing attacks to Switch B. As a result, traffic that
Gateway
10.1.1.1/24
GE1/0/3
GE1/0/2
Host B
Use the command...
1-13
Remarks
Required
Disabled by default.

Advertisement

Chapters

Table of Contents
loading

Table of Contents