Arp Inspection - Tripp Lite NGI-M08C4POE8-2 Owner's Manual

Sfp slots managed industrial ethernet poe+ switch
Table of Contents

Advertisement

This field displays how the Switch learned the binding.
Static: This binding was learned from information provided manually by
Type
an administrator.
Dynamic: This binding was learned by snooping DHCP packets.
Apply
Click Apply to configure the settings.
Refresh
Click Refresh to begin configuring this screen afresh.

7.1.3 ARP Inspection

Dynamic ARP inspection is a security feature which validates ARP packet in a network by
performing IP to MAC address binding inspection. Those will be stored in a trusted database (the
DHCP snooping database) before forwarding. Dynamic ARP intercepts, logs, and discards ARP
packets with invalid IP-to-MAC address bindings. This capability protects the network from
certain man-in-the-middle attacks.
Dynamic ARP inspection ensures that only valid ARP requests and responses are relayed.The
switch performs these activities:
Intercepts all ARP requests and responses on untrusted ports.
Verifies that each of these intercepted packets has a valid IP-to-MAC address binding before
it updates the local ARP cache or before it forwards the packet to the appropriate destination.
Trusted and untrusted port
This setting is independent of the trusted and untrusted setting of the DHCP Snooping.
The Switch does not discard ARP packets on trusted ports for any reasons.
The Switch discards ARP packets on un-trusted ports if the sender's information in the
ARP packets does not match any of the current bindings.
Normally, the trusted ports are the uplink port and the untrusted ports are connected to
subscribers.
Configurations:
Users can enable/disable the ARP Inspection on the Switch. Users also can enable/disable the
ARP Inspection on a specific VLAN. If the ARP Inspection on the Switch is disabled, the ARP
Inspection is disabled on all VLANs even some of the VLAN ARP Inspection are enabled.
Notice:
There is a global state and per VLAN states.
When the global state is disabled, the ARP Inspection on the Switch is disabled even per
VLAN states are enabled.
When the global state is enabled, user must enable per VLAN states to enable the ARP
Inspection on the specific VLAN.
244

Advertisement

Table of Contents
loading

Table of Contents