![Juniper JUNOS OS 10.3 - SOFTWARE Manual Download Page 3009](http://html.mh-extra.com/html/juniper/junos-os-10-3-software/junos-os-10-3-software_manual_20327933009.webp)
NOTE:
You can enable or disable port security on the switch at any time by
clicking the Activate or Deactivate button on the Port Security Configuration
page. If security status is shown as Disabled when you try to edit settings for
any VLANs or interfaces (ports), the message asking if you want to enable
port security appears.
Related
Documentation
Enabling a Trusted DHCP Server (CLI Procedure) on page 2912
•
•
Example: Configuring Port Security, with DHCP Snooping, DAI, MAC Limiting, and MAC
Move Limiting, on an EX Series Switch on page 2849
•
Example: Configuring a DHCP Server Interface as Untrusted to Protect the Switch from
Rogue DHCP Server Attacks on page 2859
•
Verifying That a Trusted DHCP Server Is Working Correctly on page 2935
•
Monitoring Port Security on page 2933
•
Understanding Trusted DHCP Servers for Port Security on EX Series Switches on
page 2840
Enabling Dynamic ARP Inspection (CLI Procedure)
Dynamic ARP inspection (DAI) protects EX Series switches against ARP spoofing. DAI
inspects ARP packets on the LAN and uses the information in the DHCP snooping
database on the switch to validate ARP packets and to protect against ARP cache
poisoning.
You configure DAI for each VLAN, not for each interface (port). By default, DAI is disabled
for all VLANs.
To enable dynamic ARP inspection (DAI) on a VLAN or all VLANs using the CLI:
•
On a single VLAN (here, the VLAN is
employee-vlan
):
[edit ethernet-switching-options secure-access-port]
user@switch#
set vlan employee-vlan
arp-inspection
•
On all VLANs:
[edit ethernet-switching-options secure-access-port]
user@switch#
set vlan all arp-inspection
Related
Documentation
Enabling Dynamic ARP Inspection (J-Web Procedure) on page 2914
•
•
Example: Configuring Port Security, with DHCP Snooping, DAI, MAC Limiting, and MAC
Move Limiting, on an EX Series Switch on page 2849
•
Example: Configuring DHCP Snooping, DAI , and MAC Limiting on an EX Series Switch
with Access to a DHCP Server Through a Second Switch on page 2873
2913
Copyright © 2010, Juniper Networks, Inc.
Chapter 95: Configuring Port Security
Summary of Contents for JUNOS OS 10.3 - SOFTWARE
Page 325: ...CHAPTER 17 Operational Mode Commands for System Setup 229 Copyright 2010 Juniper Networks Inc ...
Page 1323: ...CHAPTER 56 Operational Mode Commands for Interfaces 1227 Copyright 2010 Juniper Networks Inc ...
Page 2841: ...CHAPTER 86 Operational Commands for 802 1X 2745 Copyright 2010 Juniper Networks Inc ...
Page 3367: ...CHAPTER 113 Operational Mode Commands for CoS 3271 Copyright 2010 Juniper Networks Inc ...
Page 3435: ...CHAPTER 120 Operational Mode Commands for PoE 3339 Copyright 2010 Juniper Networks Inc ...
Page 3529: ...CHAPTER 126 Operational Mode Commands for MPLS 3433 Copyright 2010 Juniper Networks Inc ...