Arp Inspection; Arp Access List - SMC Networks 7824M/VSW - annexe 1 Manual

Extended ethernet switch
Hide thumbs Also See for 7824M/VSW - annexe 1:
Table of Contents

Advertisement

Management Guide
TigerAccess™ EE
i
7.12.3
7.12.3.1
SMC7824M/VSW
To set the aging time of gateway address in ARP alias, use the following command.
Command
arp
alias
aging-time
2147483647>
arp alias aging-time
Unless you input a MAC address, the MAC address of user's device will be used for ARP
response.
To display a registered ARP alias, use the following command.
Command
show arp alias

ARP Inspection

ARP provides IP communication by mapping an IP address to a MAC address. However,
a malicious user can attack ARP caches of systems by intercepting the traffic intended for
other hosts on the subnet. For example, Host B generates a broadcast message for all
hosts within the broadcast domain to obtain the MAC address associated with the IP ad-
dress of Host A. If Host C responses with an IP address of Host A (or B) and a MAC ad-
dress of Host C, Host A and Host B can use Host C's MAC address as the destination
MAC address for traffic intended for Host A and Host B.
ARP Inspection is a security feature that validates ARP packets in a network. It discards
ARP packets with invalid IP-MAC address binding.
To activate/deactivate the ARP inspection function in the system, use the following com-
mand.
Command
ip arp inspection vlan VLANS
no ip arp inspection vlan VLANS

ARP Access List

You can exclude a given range of IP addresses from the ARP inspection using ARP ac-
cess lists. ARP access lists are created by the arp access-list command on the Global
Configuration mode. ARP access list permits or denies the ARP packets of a given range
of IP addresses.
Mode
Changes the aging time of registered gateway address
<5-
in ARP alias.
5-2147483647: ARP alias gateway aging time (default:
Global
300 sec)
Deleted the configured aging time and returns to the
default settings.
Mode
Enable
Global
Shows a registered ARP alias.
Bridge
Mode
Activates ARP inspection on a specified VLAN.
VLANS: VLAN ID (1-4094)
Global
Deactivates ARP inspection on a specified VLAN.
Description
Description
Description
CLI
215

Advertisement

Table of Contents
loading

This manual is also suitable for:

Tigeraccess smc7824m/vsw

Table of Contents