Configuring Device Security
Configuring Management Security
Page 111
Configuring ARP Inspection
Classic
Address Resolution Protocol
is a TCP/IP protocol that translates IP addresses into MAC addresses. Clas-
sic ARP:
•
Permits two hosts on the same network to communicate and send packets.
•
Permits two hosts on different packets to communicate via a gateway.
•
Permits routers to send packets via a host to a different router on the same network.
•
Permits routers to send packets to a destination host via a local host.
ARP Inspection eliminates man-in-the-middle attacks, where false ARP packets are inserted into the subnet. ARP
requests and responses are inspected, and their MAC Address to IP Address binding is checked. Packets with
invalid ARP Inspection Bindings are logged and dropped. Packets are classified as:
•
Trusted
— Indicates that the interface IP and MAC address are recognized, and recorded in the
ARP Inspec-
tion List
. Trusted packets are forward without ARP Inspection.
•
Untrusted
— Indicates that the packet arrived from an interface that does not have a recognized IP and MAC
addresses. The packet is checked for:
–
Source MAC
— Compares the packet’s source MAC address against the sender’s MAC address in the
ARP request. This check is performed on both ARP requests and responses.
–
Destination MAC
— Compares the packet’s destination MAC address against the destination interface’s
MAC address. This check is performed for ARP responses.
–
IP Addresses
— Compares the ARP body for invalid and unexpected IP addresses. Addresses include
0.0.0.0, 255.255.255.255, and all IP Multicast addresses. If the packet’s IP address was not found in the
ARP Inspection List, and DHCP snooping is enabled for a VLAN, a search of the DHCP Snooping
Database is performed. If the IP address is found, the packet is valid and is forwarded. ARP inspection is
performed only on untrusted interfaces.
The ARP Inspection section contains the following screens:
•
ARP Inspection Properties
•
Defining Trusted Interfaces
•
Defining the ARP Inspection List
•
Assigning ARP Inspection VLAN Settings
Содержание DXS-3250E - xStack Switch
Страница 327: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 326...
Страница 397: ...Technical Support Contacting D Link Technical Support Page 395...
Страница 398: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 396...
Страница 399: ...Technical Support Contacting D Link Technical Support Page 397...
Страница 400: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 398...
Страница 401: ...Technical Support Contacting D Link Technical Support Page 399...
Страница 402: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 400...
Страница 403: ...Technical Support Contacting D Link Technical Support Page 401...
Страница 404: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 402...
Страница 405: ...Technical Support Contacting D Link Technical Support Page 403...
Страница 406: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 404...
Страница 407: ...Technical Support Contacting D Link Technical Support Page 405...
Страница 408: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 406...
Страница 409: ...Technical Support Contacting D Link Technical Support Page 407...
Страница 410: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 408...
Страница 411: ...Technical Support Contacting D Link Technical Support Page 409...
Страница 412: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 410...
Страница 413: ...Technical Support Contacting D Link Technical Support Page 411...
Страница 414: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 412...
Страница 415: ...Technical Support Contacting D Link Technical Support Page 413...
Страница 416: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 414...
Страница 417: ...Technical Support Contacting D Link Technical Support Page 415...
Страница 418: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 416...
Страница 419: ...Technical Support Contacting D Link Technical Support Page 417...
Страница 420: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 418...
Страница 421: ...Technical Support Contacting D Link Technical Support Page 419...
Страница 422: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 420...