Arp Detection Static-Bind - H3C S5120-SI Series Command Reference Manual

Hide thumbs Also See for S5120-SI Series:
Table of Contents

Advertisement

Default Level
2: System level
Parameters
dhcp-snooping: Implements ARP attack detection based on DHCP snooping entries. This mode is
mainly used to prevent source address spoofing attacks.
dot1x: Implements ARP attack detection based on 802.1X security entries. This mode is mainly used to
prevent source address spoofing attacks.
static-bind: Implements ARP attack detection based on static IP-to-MAC binding entries. This mode is
mainly used to prevent gateway spoofing attacks.
Description
Use the arp detection mode command to specify an ARP attack detection mode.
Use the undo arp detection mode command to cancel the specified ARP detection mode.
By default, no ARP detection mode is specified, that is, all packets are considered to be invalid.
Note that, if you specify the three modes at the same time, the system uses static IP-to-MAC bindings
first, then DHCP snooping entries, and then 802.1X security entries.
Examples
# Enable ARP detection based on both DHCP snooping entries and 802.1X security entries.
<Sysname> system-view
[Sysname] arp detection mode dhcp-snooping
[Sysname] arp detection mode dot1x

arp detection static-bind

Syntax
arp detection static-bind ip-address mac-address
undo arp detection static-bind [ ip-address ]
View
System view
Default Level
2: System level
Parameters
ip-address: IP address of the static binding.
mac-address: MAC address of the static binding, in the format of H-H-H.
Description
Use the arp detection static-bind command to configure a static IP-to-MAC binding.
Use the undo arp detection static-bind command to remove the configure static binding.
By default, no static IP-to-MAC binding is configured.
2-7

Advertisement

Table of Contents
loading

Table of Contents