1-13
To do…
Use the command…
Remarks
Enable ARP gateway protection
for a specified gateway
arp filter source
ip-address
Required
Disabled by default.
z
You can enable ARP gateway protection for up to eight gateways on a port.
z
Commands
arp filter source
and
arp filter binding
cannot be both configured on a port.
z
If ARP gateway protection works with ARP detection, MFF, and ARP snooping, ARP gateway
protection applies first.
ARP Gateway Protection Configuration Example
Network requirements
As shown in
, Host B launches gateway spoofing attacks to Switch B. As a result, traffic that
Switch B intends to send to Switch A is sent to Host B.
It is required to make proper configuration on Switch B to block such attacks.
Figure 1-3
Network diagram for ARP gateway protection configuration
Switch A
Switch B
Host A
Host B
Gateway
GE1/0/1
GE1/0/3
GE1/0/2
10.1.1.1/24
Configuration procedure
# Configure ARP gateway protection on Switch B.
<SwitchB> system-view
[SwitchB] interface GigabitEthernet 1/0/1
[SwitchB-GigabitEthernet1/0/1] arp filter source 10.1.1.1
[SwitchB-GigabitEthernet1/0/1] quit
[SwitchB] interface GigabitEthernet 1/0/2
[SwitchB-GigabitEthernet1/0/2] arp filter source 10.1.1.1
Summary of Contents for S5500-SI Series
Page 161: ...3 10 GigabitEthernet1 0 1 2 MANUAL...
Page 220: ...1 7 Clearing ARP entries from the ARP table may cause communication failures...
Page 331: ...1 7 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete...
Page 493: ...2 8...
Page 1111: ...1 10 Installing patches Installation completed and patches will continue to run after reboot...