Configuring Arp Restricted Forwarding; Configuring The Arp Detection Logging Function - H3C S5120-HI Security Configuration Manual

Hide thumbs Also See for S5120-HI:
Table of Contents

Advertisement

Step
1.
Enter system view.
2.
Enter VLAN view.
3.
Enable ARP detection for the
VLAN.
4.
Return to system view.
5.
Enable ARP packet validity
check and specify the objects to
be checked.
6.
Enter Layer 2 Ethernet
port/Layer 2 aggregate
interface view.
7.
Configure the port as a trusted
port on which ARP detection
does not apply.

Configuring ARP restricted forwarding

ARP restricted forwarding controls the forwarding of ARP packets that are received on untrusted ports
and have passed ARP detection in the following cases:
If the packets are ARP requests, they are forwarded through the trusted ports.
If the packets are ARP responses, they are forwarded according to their destination MAC address.
If no match is found in the MAC address table, they are forwarded through the trusted ports.
Before performing the following configuration, make sure you have configured the arp detection enable
command.
To enable ARP restricted forwarding:
Step
1.
Enter system view.
2.
Enter VLAN view.
3.
Enable ARP restricted forwarding.

Configuring the ARP detection logging function

The ARP detection logging function enables a device to generate ARP detection log messages when ARP
packet attacks are detected. An ARP detection log message can include the following information:
Receiving interface of the ARP packets.
Sender IP address.
Total number of ARP packets dropped.
The following is an example of an ARP detection log message:
Detected an inspection occurred on interface GigabitEthernet 1/0/1 with IP address
172.18.48.55 (Totally 10 packets dropped).
Command
system-view
vlan vlan-id
arp detection enable
quit
arp detection validate { dst-mac | ip |
src-mac } *
interface interface-type
interface-number
arp detection trust
Command
system-view
vlan vlan-id
arp restricted-forwarding enable
329
Remarks
N/A
N/A
Disabled by default.
N/A
Disabled by default.
N/A
Optional.
The port is an untrusted port
by default.
Remarks
N/A
N/A
Disabled by default

Advertisement

Table of Contents
loading

Table of Contents