Preventing The Man-In-The-Middle Attack - Huawei Quidway S3700 Series Configuration Manual

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
in a period (the default value is three minutes). This can prevent ARP packets with the bogus
gateway address from being broadcast on a VLAN.
----End

4.5.6 Preventing the Man-in-the-Middle Attack

Context
To prevent man-in-the-middle attacks, you can configure the S3700 to check ARP packets. If
the packets received on the interface or the interface in a VLAN match the binding table, the
packets are forwarded; otherwise, the packets are discarded.
In addition, you can configure the alarm function. When the number of discarded packets exceeds
the threshold, an alarm is generated.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
interface interface-type interface-number
The interface view is displayed.
Or, run:
vlan vlan-id
The VLAN view is displayed.
Step 3 Run:
arp anti-attack check user-bind enable
The IP source guard function is enabled on the interface.
By default, the interfaces or the interface in a VLAN are not enabled with the IP source guard
function.
Step 4 In the interface view, run:
arp anti-attack check user-bind check-item { ip-address | mac-address | vlan }
Or in the VLAN view, run:
arp anti-attack check user-bind check-item { ip-address | mac-address | interface }
*
The check items of ARP packets are configured.
Issue 01 (2011-07-15)
NOTE
Binding entries of DHCP users are created automatically after DHCP snooping is enabled. If a user uses
a static IP address, you need to configure the binding entry of the user manually. A DHCP snooping binding
entry consists of the IP address, MAC address, interface number, and VLAN ID of a user.
For the configuration of DHCP snooping, see
a static binding entry, see
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
3.3.2 Enabling DHCP
5.3.2 (Optional) Configuring a Static User Binding
4 ARP Security Configuration
Snooping. For the configuration of
Entry.
*
154

Advertisement

Table of Contents
loading

Table of Contents