Checking The Configuration - Huawei Quidway S3700 Series Configuration Manual

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
Context
This task is performed to enable DHCP-triggered ARP learning. When the DHCP server assigns
an IP address to the user, the S3700 obtains the MAC address of the user and generates the ARP
entry corresponding to the IP address after responding to DHCP ACK messages. In this manner,
the S3700 does not need to learn ARP entries of the user hosts.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
interface vlanif interface-number
The VLANIF interface view is displayed.
Step 3 Run:
arp learning dhcp-trigger
The S3700 is configured to learn ARP entries according to the DHCP ACK message received
on the VLANIF interface, and to discard ARP request packets for querying the destination host
of the network segment of the interface.
By default, the S3700 does not learn ARP entries when receiving DHCP ACK messages. When
the traffic passes, ARP learning is triggered.
----End

4.5.9 Checking the Configuration

Prerequisite
The configurations of ARP anti-attack are complete.
Procedure
l
l
----End
Issue 01 (2011-07-15)
NOTE
l To use the arp learning dhcp-trigger command, ensure that the DHCP relay function is enabled on
the VLANIF interface.
l If the DHCP user and DHCP server are located on the same network segment, you cannot use the arp
learning dhcp-trigger command.
Run the display arp anti-attack configuration { arp-rate-limit | arpmiss-rate-limit |
arp-speed-limit | arpmiss-speed-limit | entry-check | gateway-duplicate | log-trap-
timer | packet-check | all } and display arp anti-attack configuration check user-bind
interface interface-type interface-number commands to check the configuration of ARP
anti-attack.
Run the display arp anti-attack gateway-duplicate item command to check information
about bogus gateway address attack on the network.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
4 ARP Security Configuration
156

Advertisement

Table of Contents
loading

Table of Contents