HPE FlexNetwork 10500 Series Security Configuration Manual page 14

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Configuring authorized ARP··························································································································· 517
Configuration procedure ························································································································· 517
Configuration example (on a DHCP server)··························································································· 517
Configuration example (on a DHCP relay agent) ··················································································· 518
Configuring ARP attack detection ·················································································································· 519
Configuring user validity check ·············································································································· 520
Configuring ARP packet validity check ·································································································· 521
Configuring ARP restricted forwarding ··································································································· 522
Ignoring ingress ports of ARP packets during user validity check ························································· 522
Configuring ARP attack detection for a VSI ··························································································· 523
Enabling ARP attack detection logging ·································································································· 524
Displaying and maintaining ARP attack detection·················································································· 524
User validity check and ARP packet validity check configuration example ············································ 525
Configuring ARP scanning and fixed ARP ····································································································· 526
Configuration restrictions and guidelines ······························································································· 526
Configuration procedure ························································································································· 526
Configuring ARP gateway protection ············································································································· 527
Configuration guidelines ························································································································· 527
Configuration procedure ························································································································· 527
Configuration example ··························································································································· 527
Configuring ARP filtering ································································································································ 528
Configuration guidelines ························································································································· 528
Configuration procedure ························································································································· 528
Configuration example ··························································································································· 529
Configuring ARP sender IP address checking ······························································································· 530
Configuring ND attack defense ·································································· 531
Overview ························································································································································ 531
ND attack defense configuration task list ······································································································· 531
Enabling source MAC consistency check for ND messages ········································································· 531
Configuring ND attack detection ···················································································································· 532
About ND attack detection ····················································································································· 532
Configuration guidelines ························································································································· 532
Configuration procedure ························································································································· 533
Displaying and maintaining ND attack detection ···················································································· 533
ND attack detection configuration example···························································································· 533
Configuring RA guard····································································································································· 535
About RA guard ······································································································································ 535
Specifying the role of the attached device ····························································································· 535
Configuring an RA guard policy ············································································································· 536
Enabling the RA guard logging feature ·································································································· 536
Displaying and maintaining RA guard ···································································································· 537
RA guard configuration example ············································································································ 537
Configuring uRPF ······················································································ 540
Overview ························································································································································ 540
uRPF check modes ································································································································ 540
Cooperation with default route ··············································································································· 540
uRPF operation ······································································································································ 541
Network application ································································································································ 542
Enabling uRPF ··············································································································································· 543
Displaying and maintaining uRPF ·················································································································· 543
uRPF configuration example ·························································································································· 543
Configuring IPv6 uRPF ·············································································· 545
Overview ························································································································································ 545
IPv6 uRPF check modes ························································································································ 545
Cooperation with default route ··············································································································· 545
IPv6 uRPF operation ······························································································································ 546
Network application ································································································································ 547
Enabling IPv6 uRPF ······································································································································· 548
Displaying and maintaining IPv6 uRPF ·········································································································· 548
xii

Advertisement

Table of Contents
loading

Table of Contents