Configuration Guide
Gateway Anti-arp-spoofing Configuration
Gateway Anti-Arp-spoofing
Configuration
Overview
On a Layer 2 switch, ARP packets are broadcasted within this VLAN by default. This
makes gateway ARP spoofing possible.
Gateway ARP spoofing means as that when User A sends an ARP packet to request
the MAC address of a gateway, User B in the same VLAN will receive this ARP
packet. User B may send an ARP response packet and fill in the source IP address
of the packet with the IP address of the gateway and in the source MAC address with
its own MAC address. Upon receiving this ARP response packet, User A will consider
User B’s machine as the gateway. Thus, all the packets sent to the gateway within
the communication of User A will be sent to User B. Consequently, communication of
User A is intercepted and results in ARP spoofing.
Thus, we may configure gateway anti-arp-spoofing on the Layer 2 switches to
prevent the gateway anti-ARP-spoofing. After gateway anti-arp-spoofing has been
configured, we may check at the port whether the source IP address of an ARP
packet is the IP address of the gateway we have configured. If it is, this packet will be
discarded to prevent an user to receive a wrong ARP response packet. Thus, only
the device connected with the switch can deliver the ARP packets of the gateway.
Other PCs cannot send any counterfeit ARP response packet of the gateway.
Configuration
Setting Gateway Anti-arp-spoofing
Set the IP address of gateway anti-arp-spoofing:
Command
Function
Ruijie(config-if)#
anti-arp-spoofing
ip
ip-address
Configure gateway anti-arp-spoofing on
this port.
ip-address
: specify the IP address of the
gateway.
In the interface configuration mode, you may use the
no anti-arp-spoofing ip
ip-address
command to clear the gateway anti-arp-spoofing configuration.
Summary of Contents for RG-S2900G-E Series
Page 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Page 91: ...Configuration Guide Configuring PoE Configuration ...
Page 133: ...Configuration Guide EEE Configuration ...
Page 319: ...Configuration Guide QinQ Configuration ...
Page 408: ......
Page 409: ...IP Routing Configuration 1 Static Route Configuration ...
Page 412: ......
Page 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Page 757: ......
Page 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Page 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Page 901: ...Configuration Guide ERSPAN Configuration ...
Page 902: ...Web based Configuration 1 Web based Configuration ...