258
Network Administration: Security
FILE LOCATION: C:\Users\gina\Desktop\Checkout_new\Dell Astute\User
Guide\Dell_Astute_Network_Admin_Security.fm
D E L L C O N F ID E N T IA L – P R E L IM I N A R Y 8 / 9 /1 6 - FO R PR O O F O N L Y
8
Set
Set Port
to
Locked
.
9
Enter the following fields:
–
Action on Violation
— Select the action to be applied to packets
arriving on a locked port. The possible options are:
•
Discard
— Discard the packets from any unlearned source.
•
Forward
— Forward the packets from an unknown source,
without learning the MAC address.
•
Shutdown
— Discard the packet from any unlearned source, and
shut down the port. Ports remain shut down until they are
reactivated, or the device is reset.
–
Trap
— Enable/disable traps being sent when a packet is received on a
locked port.
–
Trap Frequency (1-1000000)
— Enter the amount of time (in
seconds) between traps.
10
Click
OK
. The feature is operational on the interface.
Dynamic ARP Inspection (DAI)
This section describes dynamic ARP inspection.
It contains the following topics:
• Overview
• Global Settings
• DAI List
• DAI Entries
• DAI VLAN Settings
• Trusted Interfaces
Overview
ARP Inspection eliminates man-in-the-middle attacks, where false ARP
packets are inserted into the subnet. ARP requests and responses are
inspected, and their MAC-address-to-IP-address binding is checked according
to the ARP Inspection List defined by the user (in the