Configuring Vlan Settings For Arp Inspection - Edge-Core ECS4810-12M Layer 2 Management Manual

Hide thumbs Also See for ECS4810-12M Layer 2:
Table of Contents

Advertisement

| Security Measures
C
14
HAPTER
ARP Inspection
C
VLAN
ONFIGURING
S
ARP
ETTINGS FOR
I
NSPECTION
IP – Checks the ARP body for invalid and unexpected IP addresses.
Sender IP addresses are checked in all ARP requests and responses,
while target IP addresses are checked only in ARP responses.
Src-MAC – Validates the source MAC address in the Ethernet
header against the sender MAC address in the ARP body. This check
is performed on both ARP requests and responses.
Log Message Number – The maximum number of entries saved in a
log message. (Range: 0-256; Default: 5)
Log Interval – The interval at which log messages are sent.
(Range: 0-86400 seconds; Default: 1 second)
W
I
EB
NTERFACE
To configure global settings for ARP Inspection:
Click Security, ARP Inspection.
1.
Select Configure General from the Step list.
2.
Enable ARP inspection globally, enable any of the address validation
3.
options, and adjust any of the logging parameters if required.
Click Apply.
4.
Figure 188: Configuring Global Settings for ARP Inspection
Use the Security > ARP Inspection (Configure VLAN) page to enable ARP
inspection for any VLAN and to specify the ARP ACL to use.
CLI R
EFERENCES
"ARP Inspection" on page 783
C
U
OMMAND
SAGE
ARP Inspection VLAN Filters (ACLs)
By default, no ARP Inspection ACLs are configured and the feature is
disabled.
– 344 –

Advertisement

Table of Contents
loading

Table of Contents