4-10
By default, ARP detection is disabled for a VLAN.
Examples
# Enable ARP detection for VLAN 1.
<Sysname> system-view
[Sysname] vlan 1
[Sysname-Vlan1] arp detection enable
arp detection mode
Syntax
arp detection mode
{
dhcp-snooping
|
dot1x | static-bind
}
undo arp detection mode
{
dhcp-snooping
|
dot1x | static-bind
}
View
System view
Default Level
2: System level
Parameters
dhcp-snooping
: Implements ARP attack detection based on DHCP snooping entries. This mode is
mainly used to prevent source address spoofing attacks.
dot1x
: Implements ARP attack detection based on 802.1X security entries. This mode is mainly used
to prevent source address spoofing attacks.
static-bind
: Implements ARP attack detection based on static IP-to-MAC binding entries. This mode is
mainly used to prevent gateway spoofing attacks.
Description
Use the
arp detection mode
command to specify an ARP attack detection mode.
Use the
undo arp detection mode
command to cancel the specified ARP detection mode.
By default, no ARP detection mode is specified, that is, all packets are considered to be invalid.
Note that, if you specify the three modes at the same time, the system uses static IP-to-MAC bindings
first, then DHCP snooping entries, and then 802.1X security entries.
Examples
# Enable ARP detection based on both DHCP snooping entries and 802.1X security entires.
<Sysname> system-view
[Sysname] arp detection mode dhcp-snooping
[Sysname] arp detection mode dot1x
arp detection static-bind
Syntax
arp detection static-bind ip-address mac-address
Summary of Contents for E4510-48G
Page 109: ...2 18 Sysname interface bridge aggregation 1 Sysname Bridge Aggregation1 shutdown ...
Page 309: ...6 4 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address dhcp alloc ...
Page 324: ...8 3 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address bootp alloc ...
Page 530: ...2 5 Sysname mvlan 100 subvlan 10 to 15 ...
Page 739: ...8 15 Sysname system view Sysname port security trap addresslearned ...
Page 819: ...13 11 Sysname system view Sysname public key peer key2 import sshkey key pub ...
Page 914: ...5 17 Sysname reset oam ...
Page 1064: ...5 30 Slot 2 Set next configuration file successfully ...
Page 1325: ...21 13 Examples Redirect to member 2 Sysname irf switch to 2 Sysname Slave 2 ...