Verifying That Ip Source Guard Is Working Correctly; Verifying That Proxy Arp Is Working Correctly - Juniper JUNOS OS 10.4 - FOR EX REV 1 Manual

For ex series ethernet switches
Table of Contents

Advertisement

Complete Software Guide for Junos
Related
Documentation

Verifying That IP Source Guard Is Working Correctly

Purpose
Action
Meaning
Related
Documentation

Verifying That Proxy ARP Is Working Correctly

Purpose
Action
3166
®
OS for EX Series Ethernet Switches, Release 10.4
Configuring MAC Move Limiting (CLI Procedure) on page 3143
Configuring MAC Move Limiting (J-Web Procedure) on page 3145
Configuring Autorecovery From the Disabled State on Secure or Storm Control Interfaces
(CLI Procedure) on page 3018
Example: Configuring Port Security, with DHCP Snooping, DAI, MAC Limiting, and MAC
Move Limiting, on an EX Series Switch on page 3073
Monitoring Port Security on page 3157
Verify that IP source guard is enabled and is mitigating the effects of any source IP
spoofing attacks on the EX Series switch.
Display the IP source guard database.
user@switch> show ip-source-guard
IP source guard information:
Interface
Tag
IP Address
ge-0/0/12.0
0
10.10.10.7
ge-0/0/13.0
0
10.10.10.9
ge—0/0/13.0
100
*
The IP source guard database table contains the VLANs enabled for IP source guard, the
untrusted access interfaces on those VLANs, the VLAN 802.1Q tag IDs if there are any,
and the IP addresses and MAC addresses that are bound to one another. If a switch
interface is associated with multiple VLANs and some of those VLANs are enabled for
IP source guard and others are not, the VLANs that are not enabled for IP source guard
have a star (*) in the
IP Address
in the preceding sample output.
Configuring IP Source Guard (CLI Procedure) on page 3147
Verify that the switch is sending proxy ARP messages.
List the system statistics for ARP:
user@switch> show system statistics arp
arp:
198319 datagrams received
45 ARP requests received
12 ARP replies received
2 resolution requests received
2 unrestricted proxy requests
0 restricted proxy requests
0 received proxy requests
MAC Address
VLAN
00:30:48:92:A5:9D
vlan100
00:30:48:8D:01:3D
vlan100
*
voice
and
MAC Address
fields. See the entry for the
Copyright © 2010, Juniper Networks, Inc.
voice
VLAN

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents