Table 102: Arp Inspection Commands - Edge-Core ECS4110-28T Management Manual

28/52-port gigabit ethernet layer 2+ switch
Hide thumbs Also See for ECS4110-28T:
Table of Contents

Advertisement

| General Security Measures
C
25
HAPTER
ARP Inspection
show ipv6
source-guard
binding
ARP I
NSPECTION
This command shows the IPv6 source guard binding table.
S
YNTAX
show ipv6 source-guard binding [dynamic | static]
dynamic - Shows dynamic entries configured with ND Snooping or
DHCPv6 Snooping commands (see
static - Shows static entries configured with the
binding
command.
C
M
OMMAND
ODE
Privileged Exec
E
XAMPLE
Console#show ipv6 source-guard binding
MAC Address
IPv6 Address
-------------- --------------------------------------- ---- --------- ----
00AB-11CD-2345
Console#
ARP Inspection validates the MAC-to-IP address bindings in Address
Resolution Protocol (ARP) packets. It protects against ARP traffic with
invalid address bindings, which forms the basis for certain "man-in-the-
middle" attacks. This is accomplished by intercepting all ARP requests and
responses and verifying each of these packets before the local ARP cache is
updated or the packet is forwarded to the appropriate destination,
dropping any invalid ARP packets.
ARP Inspection determines the validity of an ARP packet based on valid IP-
to-MAC address bindings stored in a trusted database – the DHCP snooping
binding database. ARP Inspection can also validate ARP packets against
user-configured ARP access control lists (ACLs) for hosts with statically
configured IP addresses.
This section describes commands used to configure ARP Inspection.

Table 102: ARP Inspection Commands

Command
ip arp inspection
ip arp inspection filter
ip arp inspection log-buffer
logs
ip arp inspection validate
ip arp inspection vlan
– 948 –
page
2001::1
Function
Enables ARP Inspection globally on the switch
Specifies an ARP ACL to apply to one or more VLANs GC
Sets the maximum number of entries saved in a log
message, and the rate at these messages are sent
Specifies additional validation of address
components in an ARP packet
Enables ARP Inspection for a specified VLAN or range
of VLANs
926)
ipv6 source-guard
VLAN Interface Type
1
Eth 1/5
STA
Mode
GC
GC
GC
GC

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ecs4110-28pEcs4110-52tEcs4110-52p

Table of Contents