C
HAPTER
14
| Security Measures
ARP Inspection
– 328 –
ES-4500G Series
with different MAC addresses are classified as invalid and are
dropped.
■
IP – Checks the ARP body for invalid and unexpected IP addresses.
These addresses include 0.0.0.0, 255.255.255.255, and all IP
multicast addresses. Sender IP addresses are checked in all ARP
requests and responses, while target IP addresses are checked only
in ARP responses.
■
Source MAC – Checks the source MAC address in the Ethernet
header against the sender MAC address in the ARP body. This check
is performed on both ARP requests and responses. When enabled,
packets with different MAC addresses are classified as invalid and
are dropped.
ARP Inspection Logging
◆
By default, logging is active for ARP Inspection, and cannot be disabled.
◆
The administrator can configure the log facility rate.
◆
When the switch drops a packet, it places an entry in the log buffer,
then generates a system message on a rate-controlled basis. After the
system message is generated, the entry is cleared from the log buffer.
◆
Each log entry contains flow information, such as the receiving VLAN,
the port number, the source and destination IP addresses, and the
source and destination MAC addresses.
◆
If multiple, identical invalid ARP packets are received consecutively on
the same VLAN, then the logging facility will only generate one entry in
the log buffer and one corresponding system message.
◆
If the log buffer is full, the oldest entry will be replaced with the newest
entry.
P
ARAMETERS
These parameters are displayed in the web interface:
◆
ARP Inspection Status
– Enables ARP Inspection globally.
(Default: Disabled)
◆
ARP Inspection Validation
– Enables extended ARP Inspection
Validation if any of the following options are enabled.
(Default: Disabled)
■
Dst-MAC
– Validates the destination MAC address in the Ethernet
header against the target MAC address in the body of ARP
responses.
■
IP
– Checks the ARP body for invalid and unexpected IP addresses.
Sender IP addresses are checked in all ARP requests and responses,
while target IP addresses are checked only in ARP responses.
Summary of Contents for iPECS ES-4526G
Page 1: ...USER GUIDE User Manual ES 4550G ES 4526G Managed Layer 3 Stackable GE Switch ...
Page 38: ...CONTENTS 38 ES 4500G Series ...
Page 58: ...SECTION I Getting Started 58 ES 4500G Series ...
Page 70: ...CHAPTER 1 Introduction System Defaults 70 ES 4500G Series ...
Page 86: ...SECTION I Web Configuration 86 ES 4500G Series Multicast Filtering on page 413 ...
Page 196: ...CHAPTER 6 VLAN Configuration Configuring MAC based VLANs 196 ES 4500G Series ...
Page 204: ...CHAPTER 7 Address Table Settings Clearing the Dynamic Address Table 204 ES 4500G Series ...
Page 228: ...CHAPTER 8 Spanning Tree Algorithm Configuring Interface Settings for MSTP 228 ES 4500G Series ...
Page 230: ...CHAPTER 9 Rate Limit Configuration 230 ES 4500G Series Figure 106 Configuring Rate Limits ...
Page 260: ...CHAPTER 12 Quality of Service Attaching a Policy Map to a Port 260 ES 4500G Series ...
Page 478: ...CHAPTER 17 IP Configuration Setting the Switch s IP Address IP Version 6 478 ES 4500G Series ...
Page 528: ...CHAPTER 20 IP Services Forwarding UDP Service Requests 528 ES 4500G Series ...
Page 614: ...CHAPTER 22 Multicast Routing Configuring PIMv6 for IPv6 614 ES 4500G Series ...
Page 628: ...CHAPTER 23 Using the Command Line Interface CLI Command Groups 628 ES 4500G Series ...
Page 702: ...CHAPTER 26 SNMP Commands 702 ES 4500G Series ...
Page 710: ...CHAPTER 27 Remote Monitoring Commands 710 ES 4500G Series ...
Page 868: ...CHAPTER 34 Port Mirroring Commands Local Port Mirroring Commands 868 ES 4500G Series ...
Page 890: ...CHAPTER 37 Address Table Commands 890 ES 4500G Series ...
Page 1066: ...CHAPTER 43 LLDP Commands 1066 ES 4500G Series ...
Page 1076: ...CHAPTER 44 Domain Name Service Commands 1076 ES 4500G Series ...
Page 1286: ...CHAPTER 49 Multicast Routing Commands PIM Multicast Routing 1286 ES 4500G Series ...
Page 1288: ...SECTION I Appendices 1288 ES 4500G Series ...
Page 1294: ...APPENDIX A Software Specifications Management Information Bases 1294 ES 4500G Series ...
Page 1327: ...ES 4526G ES 4550G E042011 ST R01 150200000149A ...
Page 1328: ...APRIL 2011 ISSUE 1 0 ...