Configuring The Arp Anti-Spoofing - Zte ZXA10 C300 Configuration Manual

Optical access convergence equipment
Hide thumbs Also See for ZXA10 C300:
Table of Contents

Advertisement

ZXA10 C300 Configuration Manual (CLI)
mac-move-report :enable
mac-move-report interval:30[minutes]
mac-anti-spoofing :enable
uplink-protect
4. (Optional) Query the MAC move log.
ZXAN#show security mac-move-log
Flag *--macMove is forbidden by system.
the total mac-move-log num:2
-------------------------------------------------------------------------
mac-address
index trapFlag detector queryPort
-------------------------------------------------------------------------
0002.0304.0506 100
1
-------------------------------------------------------------------------
0002.0304.0507 100
2
– End of Steps –

14.3 Configuring the ARP Anti-Spoofing

The ARP anti-spoofing prevents the ARP spoofing on user side.
Context
The ZXA10 C300 supports user-side
based on the following ARP entries:
l
The ARP entries inserted by the
l
The ARP entries of DHCP snooping static binding item configured by the IP source
Guard module
ARP anti-spoofing function is based on both VLAN and service port. Only when the
ARP anti-spoofing functions on both VLAN and service port are enabled, the system can
implement ARP anti-spoofing on ARP packets with the specific VLAN tag.
When receiving an ARP packet, the ZXA10 C300 compares the packet with the known
ARP entries. If the source IP address of the received ARP packet and the
in the ARP table, the ZXA10 C300 checks whether the
they are different, the ZXA10 C300 considers the packet as an ARP spoofing behavior and
discards it.
The
ARP
SJ-20130520164529-007|2013-06-30 (R1.0)
:enable
vlan
cfgMacProtect
UNNEED
SENDED
MP
UNNEED
UNNEED
*SENDED
MP
UNNEED
anti-spoofing function can be configured with up to 256 VLANs.
moveToPort
moveFromPort
inner-port_1/12/1
inner-port_1/5/1
inner-port_1/12/2
inner-port_1/5/1
ARP
anti-spoofing function, which is implemented
DHCP
module
14-10
moveToIfId
moveCount
moveFromIfId trapCount
unknown(0)
unknown(0)
unknown(0)
unknown(0)
MAC
addresses are the same. If
ZTE Proprietary and Confidential
1
1
1
1
VLAN
exist

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents