C
HAPTER
13
| Security Measures
ARP Inspection
– 303 –
ARP Inspection Logging
◆
By default, logging is active for ARP Inspection, and cannot be disabled.
◆
The administrator can configure the log facility rate.
◆
When the switch drops a packet, it places an entry in the log buffer,
then generates a system message on a rate-controlled basis. After the
system message is generated, the entry is cleared from the log buffer.
◆
Each log entry contains flow information, such as the receiving VLAN,
the port number, the source and destination IP addresses, and the
source and destination MAC addresses.
◆
If multiple, identical invalid ARP packets are received consecutively on
the same VLAN, then the logging facility will only generate one entry in
the log buffer and one corresponding system message.
◆
If the log buffer is full, the oldest entry will be replaced with the newest
entry.
P
ARAMETERS
These parameters are displayed in the web interface:
◆
ARP Inspection Status
– Enables ARP Inspection globally.
(Default: Disabled)
◆
ARP Inspection Validation
– Enables extended ARP Inspection
Validation if any of the following options are enabled.
(Default: Disabled)
■
Dst-MAC
– Validates the destination MAC address in the Ethernet
header against the target MAC address in the body of ARP
responses.
■
IP
– Checks the ARP body for invalid and unexpected IP addresses.
Sender IP addresses are checked in all ARP requests and responses,
while target IP addresses are checked only in ARP responses.
■
Src-MAC
– Validates the source MAC address in the Ethernet
header against the sender MAC address in the ARP body. This check
is performed on both ARP requests and responses.
◆
Log Message Number
– The maximum number of entries saved in a
log message. (Range: 0-256; Default: 5)
◆
Log Interval
– The interval at which log messages are sent.
(Range: 0-86400 seconds; Default: 1 second)
Содержание ECS4610-24F
Страница 1: ...Management Guide www edge core com ECS4610 24F 24 Port Layer 3 Gigabit Ethernet Switch...
Страница 2: ......
Страница 4: ......
Страница 6: ...ABOUT THIS GUIDE 6...
Страница 36: ...CONTENTS 36...
Страница 48: ...FIGURES 48...
Страница 54: ...TABLES 54...
Страница 56: ...SECTION I Getting Started 56...
Страница 78: ...CHAPTER 2 Initial Switch Configuration Managing System Files 78...
Страница 80: ...SECTION II Web Configuration 80 Unicast Routing on page 483 Multicast Routing on page 541...
Страница 100: ...CHAPTER 3 Using the Web Interface Navigating the Web Browser Interface 100...
Страница 123: ...CHAPTER 4 Basic Management Tasks Resetting the System 123 Figure 22 Restarting the Switch Regularly...
Страница 124: ...CHAPTER 4 Basic Management Tasks Resetting the System 124...
Страница 186: ...CHAPTER 6 VLAN Configuration Configuring MAC based VLANs 186...
Страница 194: ...CHAPTER 7 Address Table Settings Clearing the Dynamic Address Table 194...
Страница 218: ...CHAPTER 8 Spanning Tree Algorithm Configuring Interface Settings for MSTP 218...
Страница 220: ...CHAPTER 9 Rate Limit Configuration 220 Figure 103 Configuring Rate Limits...
Страница 222: ...CHAPTER 10 Storm Control Configuration 222 Figure 104 Configuring Broadcast Storm Control...
Страница 238: ...CHAPTER 11 Quality of Service Attaching a Policy Map to a Port 238...
Страница 334: ...CHAPTER 13 Security Measures DHCP Snooping 334...
Страница 429: ...CHAPTER 15 Multicast Filtering Multicast VLAN Registration 429 Figure 257 Showing All MVR Groups Assigned to a Port...
Страница 430: ...CHAPTER 15 Multicast Filtering Multicast VLAN Registration 430...
Страница 540: ...CHAPTER 20 Unicast Routing Configuring the Open Shortest Path First Protocol Version 2 540...
Страница 564: ...CHAPTER 21 Multicast Routing Configuring PIM for IPv4 564 Figure 375 Showing RP Mapping...
Страница 578: ...CHAPTER 22 Using the Command Line Interface CLI Command Groups 578...
Страница 628: ...CHAPTER 24 System Management Commands Time Range 628...
Страница 648: ...CHAPTER 25 SNMP Commands 648...
Страница 656: ...CHAPTER 26 Remote Monitoring Commands 656...
Страница 786: ...CHAPTER 30 Interface Commands 786...
Страница 800: ...CHAPTER 32 Port Mirroring Commands Local Port Mirroring Commands 800...
Страница 902: ...CHAPTER 38 Quality of Service Commands 902...
Страница 950: ...CHAPTER 39 Multicast Filtering Commands IGMP Proxy Routing 950...
Страница 968: ...CHAPTER 40 LLDP Commands 968...
Страница 978: ...CHAPTER 41 Domain Name Service Commands 978...
Страница 1084: ...CHAPTER 45 IP Routing Commands Open Shortest Path First OSPFv2 1084...
Страница 1114: ...SECTION IV Appendices 1114...
Страница 1120: ...APPENDIX A Software Specifications Management Information Bases 1120...
Страница 1142: ...COMMAND LIST 1142...
Страница 1152: ...INDEX 1152...
Страница 1153: ......
Страница 1154: ...ECS4610 24F E052010 ST R01 149100000092A...