Example For Configuring Arp Anti-Attack To Prevent Man-In-The-Middle Attacks - Huawei Quidway S3700 Series Configuration Manual

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
ARP Pkt Discard For SpeedLimit:
ARP Pkt Discard For Other:
<Quidway> display arp anti-attack gateway-duplicate item
interface
-------------------------------------------------------------------------------
GigabitEthernet0/0/1
GigabitEthernet0/0/2
-------------------------------------------------------------------------------
There are 2 records in gateway conflict table
----End
Configuration Files
#
sysname Quidway
#
vlan batch 10 20 30
#
arp speed-limit source-ip maximum 15
arp-miss speed-limit source-ip maximum 20
arp learning strict
arp anti-attack log-trap-timer 300
#
arp anti-attack entry-check fixed-mac enable
arp anti-attack gateway-duplicate enable
arp-miss speed-limit source-ip 2.2.2.2 maximum 50
arp speed-limit source-ip 2.2.4.2 maximum 10
#
interface Ethernet0/0/1
port hybrid pvid vlan 10
port hybrid tagged vlan 10
arp-limit vlan 10 maximum 20
#
interface Ethernet0/0/2
port hybrid pvid vlan 20
port hybrid tagged vlan 20
arp-limit vlan 20 maximum 20
#
interface Ethernet0/0/3
port hybrid pvid vlan 30
port hybrid untagged vlan 30
arp-limit vlan 30 maximum 20
#
return
4.7.2 Example for Configuring ARP Anti-Attack to Prevent Man-in-
the-Middle Attacks
Networking Requirements
As shown in
Ethernet 0/0/2 respectively. Assume that the user connected to Ethernet 0/0/2 is an attacker. To
prevent the man-in-the-middle attacks, you can configure the IP source guard function. After
the IP source guard function is configured on the Switch, the Switch checks the IP packets
according to the binding table. Only the IP packets that match the content of the binding table
can be forwarded; the other IP packets are discarded. In addition, you can enable the alarm
function for discarded packets.
Issue 01 (2011-07-15)
sum
IP address
2.1.1.1
2.1.1.2
Figure
4-2, two users are connected to the Switch through Ethernet 0/0/1 and
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
sum
0
3
MAC address
0000-0000-0002
0000-0000-0004
4 ARP Security Configuration
VLANID
aging time
2
153
2
179
164

Advertisement

Table of Contents
loading

Table of Contents