Security
Dynamic ARP Inspection
355
Cisco Small Business 300 Series Managed Switch Administration Guide
17
•
If a packet is valid, it is forwarded and the ARP cache is updated.
If the ARP Packet Validation option is selected (Properties page), the following
additional validation checks are performed:
•
Source MAC —
Compares the packet’s source MAC address in the
Ethernet header against the sender’s MAC address in the ARP request. This
check is performed on both ARP requests and responses.
•
Destination MAC —
Compares the packet’s destination MAC address in
the Ethernet header against the destination interface’s MAC address. This
check is performed for ARP responses.
•
IP Addresses —
Compares the ARP body for invalid and unexpected IP
addresses. Addresses include 0.0.0.0, 255.255.255.255, and all IP Multicast
addresses.
Packets with invalid ARP Inspection bindings are logged and dropped.
Up to 1024 entries can be defined in the ARP Access Control table.
Interaction Between ARP Inspection and DHCP Snooping
If DHCP Snooping is enabled, ARP Inspection uses the DHCP Snooping Binding
database in addition to the ARP access control rules. If DHCP Snooping is not
enabled, only the ARP access control rules are used.
ARP Defaults
ARP Defaults Table
Option
Default State
Dynamic ARP Inspection
Not enabled.
ARP Packet Validation
Not enabled
ARP Inspection Enabled on
VLAN
Not enabled
Log Buffer Interval
SYSLOG message generation for
dropped packets is enabled at 5
seconds interval
Содержание Small Business 300
Страница 1: ...Cisco Small Business 300 Series Managed Switch Administration Guide Release 1 3 ADMINISTRATION GUIDE ...
Страница 17: ...Cisco Small Business 300 Series Managed Switch Administration Guide 16 Contents ...
Страница 28: ...Getting Started Window Navigation 11 Cisco Small Business 300 Series Managed Switch Administration Guide 1 ...
Страница 44: ...Status and Statistics Managing RMON 27 Cisco Small Business 300 Series Managed Switch Administration Guide 2 ...
Страница 192: ...Smartport Built in Smartport Macros 175 Cisco Small Business 300 Series Managed Switch Administration Guide 10 ...
Страница 200: ...Port Management PoE Configuring PoE Settings 183 Cisco Small Business 300 Series Managed Switch Administration Guide 11 ...
Страница 376: ...Security Dynamic ARP Inspection 359 Cisco Small Business 300 Series Managed Switch Administration Guide 17 ...
Страница 428: ...Access Control Defining ACL Binding 411 Cisco Small Business 300 Series Managed Switch Administration Guide 21 ...
Страница 462: ...Quality of Service Managing QoS Statistics 445 Cisco Small Business 300 Series Managed Switch Administration Guide 22 ...
Страница 482: ...SNMP SNMP Notification Filters 465 Cisco Small Business 300 Series Managed Switch Administration Guide 23 ...