Configuring Authorized Arp; Configuration Procedure; Configuration Example (On A Dhcp Server) - HP VSR1000 Security Configuration Manual

Virtual services router
Table of Contents

Advertisement

Step
2.
Enable the ARP active
acknowledgement function.

Configuring authorized ARP

Authorized ARP entries are generated based on the DHCP clients' address leases on the DHCP server or
dynamic client entries on the DHCP relay agent. For more information about DHCP server and DHCP
relay agent, see Layer 3—IP Services Configuration Guide.
With authorized ARP enabled, an interface is disabled from learning dynamic ARP entries to prevent user
spoofing and allows only authorized clients to access network resources.

Configuration procedure

To enable authorized ARP:
Step
1.
Enter system view.
2.
Enter Layer 3 Ethernet interface or
Layer 3 Ethernet subinterface view.
3.
Enable authorized ARP on the
interface.

Configuration example (on a DHCP server)

Network requirements
Configure authorized ARP on GigabitEthernet 1/0 of Router A (a DHCP server) to ensure user validity.
Figure 92 Network diagram
Configuration procedure
1.
Configure Router A:
# Specify the IP address for GigabitEthernet 1/0.
<RouterA> system-view
[RouterA] interface GigabitEthernet 1/0
[RouterA-GigabitEthernet1/0] ip address 10.1.1.1 24
[RouterA-GigabitEthernet1/0] quit
# Configure DHCP.
[RouterA] dhcp enable
Command
arp active-ack [ strict ]
enable
Command
system-view
interface interface-type
interface-number
arp authorized enable
318
Remarks
By default, ARP active acknowledgement
function is disabled.
Remarks
N/A
N/A
By default, authorized ARP is
disabled.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents