Raisecom
ISCOM2600G-HI (A) Series Configuration Guide
10 Security
Raisecom Proprietary and Confidential
Copyright © Raisecom Technology Co., Ltd.
414
Step
Command
Description
2
Raisecom(config)#ip arp-
inspection binding dhcp-snooping
{ auto-update | static }
Configure ARP entry conversion.
3
Raisecom(config)#ip arp-
inspection vlan
vlan-list
Configure protection VLAN of
dynamic ARP inspection.
10.3.8 Configuring rate limiting on ARP packets on interface
Configure rate limiting on ARP packets on the interface for the ISCOM2600G-HI series
switch as below.
Step
Command
Description
1
Raisecom#config
Enter global configuration mode.
2
Raisecom(config)#interface
interface-type interface-
number
Enter physical layer interface
configuration mode.
3
Raisecom(config-
gigaethernet1/1/port)#ip arp-
rate-limit rate
rate-value
Configure the rate limit of ARP
packets on the interface.
10.3.9 Checking configurations
Use the following commands to check configuration results.
No.
Command
Description
1
Raisecom#show ip arp-inspection
Show configurations of dynamic ARP
inspection.
2
Raisecom#show ip arp-inspection
binding [
interface-type
interface-number
]
Show information about the dynamic
ARP inspection binding table.
3
Raisecom#show ip arp-rate-limit
Show configurations of rate limiting
on ARP packets.
10.3.10 Example for configuring dynamic ARP inspection
Networking requirements
To prevent ARP attacks, configure dynamic ARP inspection on Switch A, as shown in Figure
10-3.
Uplink GE 1/1/3 allows all ARP packets to pass.
Downlink GE 1/1/1 allows ARP packets with specified IP address 10.10.10.1 to pass.