Configuring User Validity Check - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

ARP packet validity check.
ARP restricted forwarding.
ARP detection logging.
If both ARP packet validity check and user validity check are enabled, the former one applies first,
and then the latter applies.

Configuring user validity check

The device checks user validity upon receiving an ARP packet from an ARP untrusted interface as
follows:
1.
Uses the user validity check rules to match the sender IP and MAC addresses of the ARP
packet.
If a match is found, the device processes the ARP packet according to the rule.
If no match is found, proceeds to step 2.
2.
Uses static IP source guard bindings, DHCP snooping entries, and 802.1X security entries to
match the sender IP and MAC addresses of the ARP packet.
If a match is found, the device forwards the ARP packet.
If no match is found, the device discards the ARP packet.
Static IP source guard binding entries are created by using the ip source binding command. For
more information, see
DHCP snooping entries are automatically generated by DHCP snooping. For more information, see
Layer 3—IP Services Configuration Guide.
802.1X security entries are generated by 802.1X. After a client passes 802.1X authentication and
uploads its IP address to an ARP detection enabled device, the device automatically generates an
802.1X security entry. The 802.1X client must be enabled to upload its IP address to the device. For
more information, see
Configuration guidelines
When you configure user validity check, you must specify a VLAN for an IP source guard binding
entry. Otherwise, no ARP packets can match the IP source guard binding entry.
Configuration procedure
To configure user validity check:
Step
1.
Enter system view.
2.
(Optional.) Configure a user
validity check rule.
3.
Enter VLAN view.
4.
Enable ARP detection.
5.
Return to system view.
6.
Enter Layer 2 Ethernet
interface view or Layer 2
aggregate interface view.
"Configuring IP source
"Configuring
802.1X."
Command
system-view
arp detection rule rule-id { deny |
permit } ip { any | ip-address
[ ip-address-mask ] } mac { any |
mac-address
[ mac-address-mask ] } [ vlan
vlan-id ]
vlan vlan-id
arp detection enable
quit
interface interface-type
interface-number
438
guard."
Remarks
N/A
By default, no user validity
check rule is configured.
N/A
By default, ARP detection is
disabled.
N/A
N/A

Advertisement

Table of Contents
loading

Table of Contents