Arp Detection Mode; Arp Detection Static-Bind - HP E4510-48G Command Reference Manual

4510g series
Table of Contents

Advertisement

By default, ARP detection is disabled for a VLAN.
Examples
# Enable ARP detection for VLAN 1.
<Sysname> system-view
[Sysname] vlan 1
[Sysname-Vlan1] arp detection enable

arp detection mode

Syntax
arp detection mode { dhcp-snooping | dot1x | static-bind }
undo arp detection mode { dhcp-snooping | dot1x | static-bind }
View
System view
Default Level
2: System level
Parameters
dhcp-snooping: Implements ARP attack detection based on DHCP snooping entries. This mode is
mainly used to prevent source address spoofing attacks.
dot1x: Implements ARP attack detection based on 802.1X security entries. This mode is mainly used
to prevent source address spoofing attacks.
static-bind: Implements ARP attack detection based on static IP-to-MAC binding entries. This mode is
mainly used to prevent gateway spoofing attacks.
Description
Use the arp detection mode command to specify an ARP attack detection mode.
Use the undo arp detection mode command to cancel the specified ARP detection mode.
By default, no ARP detection mode is specified, that is, all packets are considered to be invalid.
Note that, if you specify the three modes at the same time, the system uses static IP-to-MAC bindings
first, then DHCP snooping entries, and then 802.1X security entries.
Examples
# Enable ARP detection based on both DHCP snooping entries and 802.1X security entires.
<Sysname> system-view
[Sysname] arp detection mode dhcp-snooping
[Sysname] arp detection mode dot1x

arp detection static-bind

Syntax
arp detection static-bind ip-address mac-address
4-10

Advertisement

Table of Contents
loading

Table of Contents