GS2210 Series User’s Guide
309
C
H A P T E R
3 4
Anti-Arpscan
34.1 Anti-Arpscan Overview
Addr ess Resolut ion Pr ot ocol ( ARP) , RFC 826, is a pr ot ocol used t o conver t a net w or k- layer I P
addr ess t o a link- layer MAC addr ess. ARP scan is used t o scan t he net w or k of a cer t ain int er face for
alive host s. I t show s t he I P addr ess and MAC addr esses of all host s found. Hacker s could use ARP
scan t o find t ar get s in your net wor k. An t i- a r psca n is used t o det ect unusual ARP scan act ivit y and
block suspicious host s or por t s.
Unusual ARP scan act ivit y is det er m ined by por t and host t hr esholds t hat you set . A por t t hr eshold
is det er m ined by t he num ber of packet s r eceived per second on t he por t . I f t he r eceived packet rat e
is over t he t hreshold, t hen t he por t is put int o an Er r - D isa ble st at e. You can r ecover t he nor m al
st at e of t he por t m anually if t his happens and aft er you ident ify t he cause of t he pr oblem .
A host t hr eshold is det er m ined by t he num ber of ARP- r equest packet s r eceived per second. Ther e is
a global t hr eshold rat e for all host s. I f t he rat e of a host is over t he t hr eshold, t hen t hat host is
blocked by using a MAC addr ess filt er. A blocked host is r eleased aut om at ically aft er t he MAC aging
t im e expir es.
Not e: A por t - based t hr eshold m ust be lar ger t han t he host - based t hr eshold or t he host -
based t hr eshold w ill not w or k .
34.1.1 What You Can Do
•
Use t he An t i- Ar psca n St a t u s scr een (
) t o see w hat por t s ar e t r ust ed
and ar e for war ding t raffic or ar e disabled.
•
Use t he An t i- Ar psca n H ost St a t u s scr een (
) t o view blocked host s
and clear select ed ones.
•
Use t he An t i- Ar psca n Tr u st H ost scr een (
) t o cr eat e or r em ove
t r ust ed host s ident ified by I P addr ess and subnet m ask. An t i- a r psca n is not per for m ed on
t r ust ed host s.
•
Use t his An t i- Ar psca n Con figu r e scr een (
) t o enable ant i- ar pscan, set
por t and host t hr esholds as w ell as configur e por t s t o be t r ust ed or unt r ust ed.
34.1.2 What You Need to Know
•
You should set an uplink por t as a t r ust ed por t befor e enabling An t i- a r psca n so as t o pr event
t he por t fr om being shut dow n due t o r eceiving t oo m any ARP m essages.
•
When a por t is configur ed as a t r ust ed por t , An t i- a r psca n is not per for m ed on t he por t . Bot h
host and port t hr esholds ar e ignor ed for t r ust ed por t s. I f t he r eceived ARP packet rat e on a por t
or t he r eceived ARP- r equest s fr om a host exceed t he t hr esholds, t he t r ust ed por t w ill not be
closed.
•
I f a por t on t he Swit ch is closed by An t i- a r psca n , and you want t o r ecover it , t hen do one of t he
following: