Chapter 21 IP Source Guard
ONU User’s Guide
160
• The
ARP Inspection VLAN Configure
screen lets you enable ARP inspection on each
VLAN and to specify when the ONU generates log messages for receiving ARP packets
from each VLAN (
21.1.2 What You Need to Know About the IP Source Guard Screens
The following terms and concepts may help as you read through this chapter.
ARP Inspection
Use ARP inspection to filter unauthorized ARP packets on the network. This can prevent
many kinds of man-in-the-middle attacks, such as the one in the following example.
Figure 79
Example: Man-in-the-middle Attack
In this example, computer
B
tries to establish a connection with computer
A
. Computer
X
is in
the same broadcast domain as computer
A
and intercepts the ARP request for computer
A
.
Then, computer
X
does the following things:
• It pretends to be computer
A
and responds to computer
B
.
• It pretends to be computer
B
and sends a message to computer
A
.
As a result, all the communication between computer
A
and computer
B
passes through
computer
X
. Computer
X
can read and alter the information passed between them.
ARP Inspection and MAC Address Filters
When the ONU identifies an unauthorized ARP packet, it automatically creates a MAC
address filter to block traffic from the source MAC address and source VLAN ID of the
unauthorized ARP packet. You can configure how long the MAC address filter remains in the
ONU.
These MAC address filters are different than regular MAC address filters (
• They are stored only in volatile memory.
• They do not use the same space in memory that regular MAC address filters use.
• They appear only in the
ARP Inspection
screens and commands, not in the
MAC
Address Filter
screens and commands.
A
X
B
Summary of Contents for ONU-2024 Series
Page 2: ......
Page 7: ...Safety Warnings ONU User s Guide 7 This product is recyclable Dispose of it properly...
Page 8: ...Safety Warnings ONU User s Guide 8...
Page 20: ...Table of Contents ONU User s Guide 20...
Page 28: ...List of Tables ONU User s Guide 28...
Page 30: ...30...
Page 38: ...Chapter 2 Hardware Installation and Connection ONU User s Guide 38...
Page 44: ...Chapter 3 Hardware Connections ONU User s Guide 44...
Page 46: ...46...
Page 64: ...Chapter 6 System Status and Port Statistics ONU User s Guide 64...
Page 76: ...Chapter 7 Basic Setting ONU User s Guide 76...
Page 78: ...78...
Page 108: ...Chapter 11 Spanning Tree Protocol ONU User s Guide 108...
Page 158: ...Chapter 20 Authentication Accounting ONU User s Guide 158...
Page 174: ...Chapter 22 Loop Guard ONU User s Guide 174...
Page 175: ...175 PART IV IP Application Static Route 177 Differentiated Services 181 DHCP 185...
Page 176: ...176...
Page 180: ...Chapter 23 Static Route ONU User s Guide 180...
Page 192: ...192...
Page 216: ...Chapter 27 Access Control ONU User s Guide 216...
Page 222: ...Chapter 29 Syslog ONU User s Guide 222...
Page 236: ...236...
Page 254: ...Appendix C Legal Information ONU User s Guide 254...
Page 260: ...Appendix D Customer Support ONU User s Guide 260...
Page 268: ...Index ONU User s Guide 268...