Arp Scanning Prevention Troubleshooting; Arp Scanning Prevention Debug Command List - Digitalchina Networks DCS-3950 series Manual

Table of Contents

Advertisement

Command mode:Global Mode
User Guide: After enabling ARP scanning prevention log function, users can check the
detailed information of ports being closed or automatically recovered by ARP scanning
prevention or IP being disabled and recovered by ARP scanning prevention. The level of
the log is 'Warning'.
Example:Enable ARP scanning prevention log function of the switch
Switch(Config)#anti-arpscan log enable
21.2.2.9 anti-arpscan trap enable
Command:anti-arpscan trap enable
no anti-arpscan trap enable
Function:Enable ARP scanning prevention SNMP Trap function;' no anti-arpscan trap
enable' command disable ARP scanning prevention SNMP Trap function.
Parameters:None.
Default:Disable ARP scanning prevention SNMP Trap function
Command mode:Global Mode
User Guide: After enabling ARP scanning prevention SNMP Trap function, users will
receive Trap message whenever a port is closed or recovered by ARP scanning
prevention, and whenever IP t is closed or recovered by ARP scanning prevention
Example:Enable ARP scanning prevention SNMP Trap function of the switch
Switch(Config)#anti-arpscan trap enable

21.3 ARP Scanning Prevention Troubleshooting

ARP scanning prevention is disabled by default. After enabling ARP scanning
prevention, users can enable the debug switch, 'debug anti-arpscan', to view debug
information.
If the state of a port is showed as not closed when using 'show anti-arpscan', It
means that the port is not closed by the ARP scanning prevention function. If the port is
closed by other modules, users can check it with 'show interface'.
The max number of IP that can be disabled by IP-based ARP scanning prevention is
128. If the limit is exceeded, users will see a prompt.

21.3.1 ARP Scanning Prevention Debug Command List

21.3.1.1 show anti-arpscan [trust <ip|port|supertrust-port> |
prohibited <ip|port>]
Command:show anti-arpscan [trust <ip | port | supertrust-port> |prohibited <ip |
port>]
DCS-3950 series Ethernet switch manual
339

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents