Anti-Arpscan Trust; Anti-Arpscan Trust Ip - Edge-Core ES4624-SFP Basic Management Manual

Hide thumbs Also See for ES4624-SFP:
Table of Contents

Advertisement

the threshold of IP-based ARP scanning prevention, or, the IP-based ARP scanning
prevention will fail.
Example:Set the threshold of IP-based ARP scanning prevention as 6 packets/second.
Switch(config)#anti-arpscan ip-based threshold 6

21.3.4 anti-arpscan trust

Command:anti-arpscan trust <port | supertrust-port>
no anti-arpscan trust <port | supertrust-port>
Function: Configure a port as a trusted port or a super trusted port; "no anti-arpscan trust
<port | supertrust-port>" command will reset the port as an untrusted port.
Parameters:None.
Default Settings:By default all the ports are non- trustful.
Command Mode:Port configuration mode.
User Guide:If a port is configured as a trusted port, then the ARP scanning prevention
function will not deal with this port, even if the rate of received ARP messages exceeds
the set threshold, this port will not be closed, but the non- trustful IP of this port will still be
checked. If a port is set as a super non- trustful port, then neither the port nor the IP of
the port will be dealt with. If the port is already closed by ARP scanning prevention, it will
be opened right after being set as a trusted port.
When remotely managing a switch with a method like telnet, users should set the uplink
port as a Super Trust port before enabling anti-ARP-scan function, preventing the port
from being shutdown because of receiving too many ARP messages. After the
anti-ARP-scan function is disabled, this port will be reset to its default attribute, that is,
Untrust port.
Example:Set port ethernet 1/5 of the switch as a trusted port.
Switch(config)#in e1/5
Switch(Config-If-Ethernet1/5)# anti-arpscan trust port

21.3.5 anti-arpscan trust ip

Command:anti-arpscan trust ip <ip-address [<netmask>]>
no anti-arpscan trust ip <ip-address [<netmask>]>
Function:Configure trusted IP; "no anti-arpscan trust ip <ip-address [<netmask>]>"
command reset the IP to non-trustful IP.
Parameters:Net mask of the IP
Default Settings:By default all the IP are non-trustful. Default mask is 255.255.255.255
Command Mode:Global configuration mode
534

Advertisement

Table of Contents
loading

This manual is also suitable for:

Es4626-sfp

Table of Contents