1-7
To do…
Use the command…
Remarks
Configure the port as a trusted
port on which ARP detection
does not apply
arp detection trust
Optional
The port is an untrusted port by
default.
Enabling ARP Detection Based on Static IP Source Guard Binding Entries/DHCP
Snooping Entries/802.1X Security Entries/OUI MAC Addresses
With this feature enabled, the device compares the sender IP and MAC addresses of an ARP packet
received from the VLAN against the static IP Source Guard binding entries, DHCP snooping entries,
802.1X security entries, or OUI MAC addresses to prevent spoofing.
After you enable this feature for a VLAN,
z
Upon receiving an ARP packet from an ARP untrusted port, the device compares the sender IP
and MAC addresses of the ARP packet against the static IP Source Guard binding entries. If a
match is found, the ARP packet is considered valid and is forwarded. If an entry with a matching IP
address but an unmatched MAC address is found, the ARP packet is considered invalid and is
discarded. If no entry with a matching IP address is found, the device compares the ARP packet’s
sender IP and MAC addresses against the DHCP snooping entries, 802.1X security entries, and
OUI MAC addresses.
z
If a match is found in any of the entries, the ARP packet is considered valid and is forwarded. ARP
detection based on OUI MAC addresses refers to that if the sender MAC address of the received
ARP packet is an OUI MAC address and voice VLAN is enabled, the packet is considered valid.
z
If no match is found, the ARP packet is considered invalid and is discarded.
z
Upon receiving an ARP packet from an ARP trusted port, the device does not check the ARP
packet.
z
Static IP Source Guard binding entries are created by using the
user-bind
command. For details,
refer to
IP Source Guard Configuration
in the
Security Volume
.
z
Dynamic DHCP snooping entries are automatically generated through the DHCP snooping
function. For details, refer to
DHCP Configuration
in the
IP Service Volume
.
z
802.1X security entries are generated by the 802.1X function. For details, refer to
802.1X
Configuration
in the
Security Volume
.
Follow these steps to enable ARP detection for a VLAN and specify a trusted port:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter VLAN view
vlan vlan-id
—
Summary of Contents for S5500-SI Series
Page 161: ...3 10 GigabitEthernet1 0 1 2 MANUAL...
Page 220: ...1 7 Clearing ARP entries from the ARP table may cause communication failures...
Page 331: ...1 7 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete...
Page 493: ...2 8...
Page 1111: ...1 10 Installing patches Installation completed and patches will continue to run after reboot...