![D-Link DXS-3227 - xStack Switch - Stackable Web/Installation Manual Download Page 112](http://html.mh-extra.com/html/d-link/dxs-3227-xstack-switch-stackable/dxs-3227-xstack-switch-stackable_web-installation-manual_78174112.webp)
Configuring Device Security
Configuring Management Security
Page 111
Configuring ARP Inspection
Classic
Address Resolution Protocol
is a TCP/IP protocol that translates IP addresses into MAC addresses. Clas-
sic ARP:
•
Permits two hosts on the same network to communicate and send packets.
•
Permits two hosts on different packets to communicate via a gateway.
•
Permits routers to send packets via a host to a different router on the same network.
•
Permits routers to send packets to a destination host via a local host.
ARP Inspection eliminates man-in-the-middle attacks, where false ARP packets are inserted into the subnet. ARP
requests and responses are inspected, and their MAC Address to IP Address binding is checked. Packets with
invalid ARP Inspection Bindings are logged and dropped. Packets are classified as:
•
Trusted
— Indicates that the interface IP and MAC address are recognized, and recorded in the
ARP Inspec-
tion List
. Trusted packets are forward without ARP Inspection.
•
Untrusted
— Indicates that the packet arrived from an interface that does not have a recognized IP and MAC
addresses. The packet is checked for:
–
Source MAC
— Compares the packet’s source MAC address against the sender’s MAC address in the
ARP request. This check is performed on both ARP requests and responses.
–
Destination MAC
— Compares the packet’s destination MAC address against the destination interface’s
MAC address. This check is performed for ARP responses.
–
IP Addresses
— Compares the ARP body for invalid and unexpected IP addresses. Addresses include
0.0.0.0, 255.255.255.255, and all IP Multicast addresses. If the packet’s IP address was not found in the
ARP Inspection List, and DHCP snooping is enabled for a VLAN, a search of the DHCP Snooping
Database is performed. If the IP address is found, the packet is valid and is forwarded. ARP inspection is
performed only on untrusted interfaces.
The ARP Inspection section contains the following screens:
•
ARP Inspection Properties
•
Defining Trusted Interfaces
•
Defining the ARP Inspection List
•
Assigning ARP Inspection VLAN Settings
Summary of Contents for DXS-3227 - xStack Switch - Stackable
Page 327: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 326 ...
Page 397: ...Technical Support Contacting D Link Technical Support Page 395 ...
Page 398: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 396 ...
Page 399: ...Technical Support Contacting D Link Technical Support Page 397 ...
Page 400: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 398 ...
Page 401: ...Technical Support Contacting D Link Technical Support Page 399 ...
Page 402: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 400 ...
Page 403: ...Technical Support Contacting D Link Technical Support Page 401 ...
Page 404: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 402 ...
Page 405: ...Technical Support Contacting D Link Technical Support Page 403 ...
Page 406: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 404 ...
Page 407: ...Technical Support Contacting D Link Technical Support Page 405 ...
Page 408: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 406 ...
Page 409: ...Technical Support Contacting D Link Technical Support Page 407 ...
Page 410: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 408 ...
Page 411: ...Technical Support Contacting D Link Technical Support Page 409 ...
Page 412: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 410 ...
Page 413: ...Technical Support Contacting D Link Technical Support Page 411 ...
Page 414: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 412 ...
Page 415: ...Technical Support Contacting D Link Technical Support Page 413 ...
Page 416: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 414 ...
Page 417: ...Technical Support Contacting D Link Technical Support Page 415 ...
Page 418: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 416 ...
Page 419: ...Technical Support Contacting D Link Technical Support Page 417 ...
Page 420: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 418 ...
Page 421: ...Technical Support Contacting D Link Technical Support Page 419 ...
Page 422: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 420 ...