Enabling Arp Detection Logging; Displaying And Maintaining Arp Detection; User Validity Check And Arp Packet Validity Check Configuration Example - HPE Moonshot 45Gc Security Configuration Manual

Switch module
Table of Contents

Advertisement

Enabling ARP detection logging

The ARP detection logging feature enables a device to generate ARP detection log messages when
illegal ARP packets are detected. An ARP detection log message contains the following information:
Receiving interface of the ARP packets.
Sender IP address.
Total number of dropped ARP packets.
To enable ARP detection logging:
Step
1.
Enter system view.
2.
Enable ARP detection
logging.

Displaying and maintaining ARP detection

Execute display commands in any view and reset commands in user view.
Task
Display the VLANs enabled with
ARP detection.
Display the ARP detection
statistics.
Clear the ARP detection statistics.
User validity check and ARP packet validity check
configuration example
Network requirements
As shown in
10. Switch B performs ARP packet validity check and user validity check based on static IP source
guard bindings and DHCP snooping entries for connected hosts.
Command
system-view
arp detection log enable
Figure
126, configure DHCP snooping on Switch B, and enable ARP detection in VLAN
Command
display arp detection
display arp detection statistics [ interface interface-type
interface-number ]
reset arp detection statistics [ interface interface-type
interface-number ]
414
Remarks
N/A
By default, ARP detection logging
is disabled.

Advertisement

Table of Contents
loading

Table of Contents