Configuring The Arp Packet Rate Limit Function - 3Com 4500 PWR 26-Port Configuration Manual

Hide thumbs Also See for 4500 PWR 26-Port:
Table of Contents

Advertisement

To do...
Specify the current port as a
trusted port
Configure the port as an ARP
trusted port
Quit to system view
Enter VLAN view
Enable the ARP attack
detection function
Enable ARP restricted
forwarding
When most clients acquire IP addresses through DHCP and some clients use static IP addresses,
you need to enable DHCP snooping and configure static IP binding entries on the switch. These
functions can cooperate with ARP attack detection to check the validity of packets.
You need to use ARP attack detection based on authenticated 802.1x clients together with
functions of both MAC-based 802.1x authentication and ARP attack detection.
Currently, the VLAN ID of an IP-to-MAC binding configured on a port of an S4500 series Ethernet
switch is the same as the default VLAN ID of the port. If the VLAN tag of an ARP packet is different
from the default VLAN ID of the receiving port, the ARP packet cannot pass the ARP attack
detection based on the IP-to-MAC bindings.
Before enabling ARP restricted forwarding, make sure you have enabled ARP attack detection and
configured ARP trusted ports.
You are not recommended to configure ARP attack detection on the ports of a fabric or an
aggregation group.

Configuring the ARP Packet Rate Limit Function

Follow these steps to configure the ARP packet rate limit function:
To do...
Enter system view
Enter Ethernet port view
Use the command...
dhcp-snooping trust
arp detection trust
quit
vlan vlan-id
arp detection enable
arp restricted-forwarding
enable
Use the command...
system-view
interface interface-type
interface-number
37-7
Remarks
Optional
After DHCP snooping is
enabled, you need to configure
the upstream port connected to
the DHCP server as a trusted
port.
Optional
By default, a port is an ARP
untrusted port.
Generally, the upstream port of
a switch is configured as a
trusted port.
Required
By default, ARP attack
detection is disabled on all
ports.
Optional
Disabled by default.
Remarks

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

4500 26-port4500 50-port

Table of Contents