![SNR S2940-8G-v2 Configuration Manual Download Page 207](http://html1.mh-extra.com/html/snr/s2940-8g-v2/s2940-8g-v2_configuration-manual_1310630207.webp)
SNR S2940-8G-v2 Switch Configuration Guide
ARP Scanning Prevention Function Configuration
Chapter 30
ARP Scanning Prevention Function
Configuration
30.1
Introduction to ARP Scanning Prevention Function
ARP scanning is a common method of network attack. In order to detect all the active hosts in a
network segment, the attack source will broadcast lots of ARP messages in the segment, which
will take up a large part of the bandwidth of the network. It might even do large-traffic-attack in the
network via fake ARP messages to collapse of the network by exhausting the bandwidth. Usu-
ally ARP scanning is just a preface of other more dangerous attack methods, such as automatic
virus infection or the ensuing port scanning, vulnerability scanning aiming at stealing information,
distorted message attack, and DOS attack, etc.
Since ARP scanning threatens the security and stability of the network with great danger, so it
is very significant to prevent it. Switch provides a complete resolution to prevent ARP scanning:
if there is any host or port with ARP scanning features is found in the segment, the switch will cut
off the attack source to ensure the security of the network.
There are two methods to prevent ARP scanning: port-based and IP-based. The port-based
ARP scanning will count the number to ARP messages received from a port in a certain time range,
if the number is larger than a preset threshold, this port will be 'down'. The IP-based ARP scanning
will count the number to ARP messages received from an IP in the segment in a certain time range,
if the number is larger than a preset threshold, any traffic from this IP will be blocked, while the
port related with this IP will not be 'down'. These two methods can be enabled simultaneously.
After a port or an IP is disabled, users can recover its state via automatic recovery function.
To improve the effect of the switch, users can configure trusted ports and IP, the ARP messages
from which will not be checked by the switch. Thus the load of the switch can be effectively
decreased.
30.2
ARP Scanning Prevention Configuration Task Sequence
1. Enable the ARP Scanning Prevention function.
2. Configure the threshold of the port-based and IP-based ARP Scanning Prevention
3. Configure trusted ports
207
Summary of Contents for S2940-8G-v2
Page 11: ...SNR S2940 8G v2 Switch Configuration Guide Part I Basic Management Configuration 11...
Page 46: ...SNR S2940 8G v2 Switch Configuration Guide Part II Port Configuration 46...
Page 123: ...SNR S2940 8G v2 Switch Configuration Guide Part III VLAN and MAC Table Configuration 123...
Page 164: ...SNR S2940 8G v2 Switch Configuration Guide Part IV MSTP Configuration 164...
Page 198: ...SNR S2940 8G v2 Switch Configuration Guide Part VI L3 Forward and ARP Configuration 198...
Page 218: ...SNR S2940 8G v2 Switch Configuration Guide Part VII DHCP Configuration 218...
Page 257: ...SNR S2940 8G v2 Switch Configuration Guide Part VIII Multicast Protocol 257...
Page 278: ...SNR S2940 8G v2 Switch Configuration Guide Part IX Security Function Configuration 278...
Page 376: ...SNR S2940 8G v2 Switch Configuration Guide Part X Reliability Configuration 376...
Page 395: ...SNR S2940 8G v2 Switch Configuration Guide Part XI Flow Monitor Configuration 395...
Page 403: ...SNR S2940 8G v2 Switch Configuration Guide Part XII Network Time Management Configuration 403...
Page 411: ...SNR S2940 8G v2 Switch Configuration Guide Part XIII Debugging and Diagnosis 411...