1-14
After the above configuration is complete, Switch B will discard the ARP packets whose source IP
address is that of the gateway.
Configuring ARP Filtering
Introduction
To prevent gateway spoofing and user spoofing, the ARP filtering feature controls the forwarding of
ARP packets on a port as follows:
The port checks the sender IP and MAC addresses in a received ARP packet against configured ARP
filtering entries. If a match is found, the packet is handled normally. If not, the packet is discarded.
Configuration Procedure
Follow these steps to configure ARP filtering:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter Layer 2 Ethernet interface
view
interface interface-type
interface-number
—
Configure an ARP filtering entry
arp filter binding
ip-address
mac-address
Required
Not configured by default.
z
You can configure up to eight ARP filtering entries on a port.
z
Commands
arp filter source
and
arp filter binding
cannot be both configured on a port.
z
If ARP filtering works with ARP detection, MFF, and ARP snooping, ARP filtering applies first.
ARP Filtering Configuration Example
Network requirements
As shown in
, the IP and MAC addresses of Host A are 10.1.1.2 and 000f-e349-1233
respectively. The IP and MAC addresses of Host B are 10.1.1.3 and 000f-e349-1234 respectively.
Configure ARP filtering on GigabitEthernet1/0/1 and GigabitEthernet1/0/2 of Switch B to permit specific
ARP packets only.
Summary of Contents for S5500-SI Series
Page 161: ...3 10 GigabitEthernet1 0 1 2 MANUAL...
Page 220: ...1 7 Clearing ARP entries from the ARP table may cause communication failures...
Page 331: ...1 7 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete...
Page 493: ...2 8...
Page 1111: ...1 10 Installing patches Installation completed and patches will continue to run after reboot...