11-22
Configuring Advanced Threat Protection
Dynamic IP Lockdown
Monitoring Dynamic ARP Protection
When dynamic ARP protection is enabled, you can monitor and troubleshoot
the validation of ARP packets with the
debug arp-protect
command. Use this
command when you want to debug the following conditions:
■
The switch is dropping valid ARP packets that should be allowed.
■
The switch is allowing invalid ARP packets that should be dropped.
Figure 11-3. Example of debug arp-protect Command
Dynamic IP Lockdown
The Dynamic IP Lockdown feature is used to prevent IP source address
spoofing on a per-port and per-VLAN basis. When dynamic IP lockdown is
enabled, IP packets in VLAN traffic received on a port are forwarded only if
they contain a known source IP address and MAC address binding for the port.
The IP-to-MAC address binding can either be statically configured or learned
by the DHCP Snooping feature.
HP Switch(config)# debug arp-protect
1. ARP request is valid
"DARPP: Allow ARP request 000000-000001,10.0.0.1 for 10.0.0.2 port A1,
vlan "
2. ARP request detected with an invalid binding
"DARPP: Deny ARP request 000000-000003,10.0.0.1 port 1, vlan 1"
3. ARP response with a valid binding
"DARPP: Allow ARP reply 000000-000002,10.0.0.2 port 2, vlan 1"
4.ARP response detected with an invalid binding
"DARPP: Deny ARP reply 000000-000003,10.0.0.2 port 2, vlan 1"
Summary of Contents for E3800 Series
Page 2: ......
Page 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Page 30: ...xxviii ...
Page 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Page 186: ...4 72 Web and MAC Authentication Client Status ...
Page 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Page 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 730: ...20 Index ...
Page 731: ......