Configuring Arp Restricted Forwarding; Enabling Arp Detection Logging - HPE FlexFabric 7900 Series Security Configuration Manual

Hide thumbs Also See for FlexFabric 7900 Series:
Table of Contents

Advertisement

Step
3.
Enable ARP detection.
4.
Return to system view.
5.
Enable ARP packet validity check
and specify the objects to be
checked.
6.
Enter Layer 2 Ethernet interface
view.
7.
(Optional.) Configure the interface
as a trusted interface excluded
from ARP detection.

Configuring ARP restricted forwarding

NOTE:
ARP restricted forwarding does not apply to ARP packets with multiport MAC as their destination
MAC addresses.
ARP restricted forwarding controls the forwarding of ARP packets that are received on untrusted
interfaces and have passed user validity check as follows:
If the packets are ARP requests, they are forwarded through the trusted interface.
If the packets are ARP replies, they are forwarded according to their destination MAC address.
If no match is found in the MAC address table, they are forwarded through the trusted interface.
Configure user validity check before you configure ARP restricted forwarding.
To enable ARP restricted forwarding:
Step
1.
Enter system view.
2.
Enter VLAN view.
3.
Enable ARP restricted forwarding.

Enabling ARP detection logging

IMPORTANT:
This feature is available in Release 2137 and later versions.
The ARP detection logging feature enables a device to generate ARP detection log messages when
illegal ARP packets are detected. An ARP detection log message contains the following information:
1.
Receiving interface of the ARP packets.
2.
Sender IP address.
3.
Total number of dropped ARP packets.
The following is an example of an ARP detection log message:
Detected an inspection occurred on interface FortyGigE1/0/1 with IP address 172.18.48.55
(Total 10 packets dropped).
Command
arp detection enable
quit
arp detection validate
{ dst-mac | ip | src-mac }
*
interface interface-type
interface-number
arp detection trust
Command
system-view
vlan vlan-id
arp restricted-forwarding
enable
194
Remarks
By default, ARP detection is
disabled.
N/A
By default, ARP packet validity
check is disabled.
N/A
By default, an interface is untrusted.
Remarks
N/A
N/A
By default, ARP restricted
forwarding is disabled.

Advertisement

Table of Contents
loading

Table of Contents