Arp Scanning Prevention Typical Examples - Planet XGS3-42000R User Manual

4-slot layer 3 ipv6/ ipv4 routing chassis switch
Table of Contents

Advertisement

Admin Mode
debug anti-arpscan <port | ip>
no debug anti-arpscan <port | ip>

22.3 ARP Scanning Prevention Typical Examples

Figure 22-3-1 A RP scanning prevention typical configuration example
In the net work topology above, port E1/1 of SWITCH B is connected to port E1/19 of SWITCH A, the port E1/2
of SWITCH A is connected to file server (IP address is 192.168. 1.100), and all the other ports of SWITCH A
are connected to common P C. The following configuration can prevent ARP scanning effectively without
affecting the normal operation of the system.
SWITCH A configuration task sequence:
SwitchA(config)#anti-arpscan enable
SwitchA(config)#anti-arpscan recovery time 3600
SwitchA(config)#anti-arpscan trust ip 192.168.1.0 255.255.255.0
SwitchA(config)#int erface et hernet1/2
SwitchA (Config-If-Ethernet1/2)#anti-arpscan trust port
SwitchA (Config-If-Ethernet1/2)#exit
SwitchA(config)#int erface et hernet1/19
SwitchA (Config-If-Ethernet1/19)#anti-arpscan trust supertrust-port
Switch A(Config-If-Ethernet1/19)#exit
Enable or disable the debug switch of A RP
scanning prevention.
E1/1
E1/19
E1/2
E1/2
PC
Server
192.168.1.100/24
22-3
SWITCH B
SWITCH A
PC

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents