C
HAPTER
14
| Security Measures
ARP Inspection
– 343 –
■
Destination MAC – Checks the destination MAC address in the
Ethernet header against the target MAC address in the ARP body.
This check is performed for ARP responses. When enabled, packets
with different MAC addresses are classified as invalid and are
dropped.
■
IP – Checks the ARP body for invalid and unexpected IP addresses.
These addresses include 0.0.0.0, 255.255.255.255, and all IP
multicast addresses. Sender IP addresses are checked in all ARP
requests and responses, while target IP addresses are checked only
in ARP responses.
■
Source MAC – Checks the source MAC address in the Ethernet
header against the sender MAC address in the ARP body. This check
is performed on both ARP requests and responses. When enabled,
packets with different MAC addresses are classified as invalid and
are dropped.
ARP Inspection Logging
◆
By default, logging is active for ARP Inspection, and cannot be disabled.
◆
The administrator can configure the log facility rate.
◆
When the switch drops a packet, it places an entry in the log buffer,
then generates a system message on a rate-controlled basis. After the
system message is generated, the entry is cleared from the log buffer.
◆
Each log entry contains flow information, such as the receiving VLAN,
the port number, the source and destination IP addresses, and the
source and destination MAC addresses.
◆
If multiple, identical invalid ARP packets are received consecutively on
the same VLAN, then the logging facility will only generate one entry in
the log buffer and one corresponding system message.
◆
If the log buffer is full, the oldest entry will be replaced with the newest
entry.
P
ARAMETERS
These parameters are displayed:
◆
ARP Inspection Status
– Enables ARP Inspection globally.
(Default: Disabled)
◆
ARP Inspection Validation
– Enables extended ARP Inspection
Validation if any of the following options are enabled.
(Default: Disabled)
■
Dst-MAC
– Validates the destination MAC address in the Ethernet
header against the target MAC address in the body of ARP
responses.
Содержание ECS4810-12M Layer 2
Страница 1: ...Management Guide www edge core com ECS4810 12M Layer 2 Gigabit Ethernet Switch...
Страница 2: ......
Страница 4: ......
Страница 6: ...ABOUT THIS GUIDE 6...
Страница 54: ...SECTION I Getting Started 54...
Страница 64: ...CHAPTER 1 Introduction System Defaults 64...
Страница 82: ...CHAPTER 2 Initial Switch Configuration Managing System Files 82...
Страница 84: ...SECTION II Web Configuration 84...
Страница 102: ...CHAPTER 3 Using the Web Interface Navigating the Web Browser Interface 102...
Страница 206: ...CHAPTER 6 VLAN Configuration Configuring VLAN Mirroring 206...
Страница 256: ...CHAPTER 11 Class of Service Layer 3 4 Priority Settings 256...
Страница 378: ...CHAPTER 14 Security Measures DHCP Snooping 378...
Страница 520: ...CHAPTER 16 IP Configuration Setting the Switch s IP Address IP Version 6 520...
Страница 528: ...CHAPTER 17 IP Services Displaying the DNS Cache 528...
Страница 586: ...CHAPTER 19 Using the Command Line Interface CLI Command Groups 586...
Страница 676: ...CHAPTER 22 SNMP Commands 676...
Страница 684: ...CHAPTER 23 Remote Monitoring Commands 684...
Страница 816: ...CHAPTER 27 Access Control Lists ACL Information 816...
Страница 866: ...CHAPTER 30 Port Mirroring Commands RSPAN Mirroring Commands 866...
Страница 883: ...CHAPTER 32 Automatic Traffic Control Commands 883 Trap Traffic Release Disabled Disabled Console...
Страница 884: ...CHAPTER 32 Automatic Traffic Control Commands 884...
Страница 890: ...CHAPTER 33 Address Table Commands 890...
Страница 986: ...CHAPTER 37 Class of Service Commands Priority Commands Layer 3 and 4 986...
Страница 1006: ...CHAPTER 38 Quality of Service Commands 1006...
Страница 1068: ...CHAPTER 39 Multicast Filtering Commands Multicast VLAN Registration 1068...
Страница 1092: ...CHAPTER 40 LLDP Commands 1092...
Страница 1134: ...CHAPTER 41 CFM Commands 1134...
Страница 1154: ...CHAPTER 43 Domain Name Service Commands 1154...
Страница 1160: ...CHAPTER 44 DHCP Commands DHCP Client 1160...
Страница 1194: ...CHAPTER 45 IP Interface Commands IPv6 Interface 1194...
Страница 1196: ...SECTION IV Appendices 1196...
Страница 1201: ...APPENDIX A Software Specifications Management Information Bases 1201 Trap RFC 1215 UDP MIB RFC 2013...
Страница 1202: ...APPENDIX A Software Specifications Management Information Bases 1202...
Страница 1224: ...COMMAND LIST 1224...
Страница 1234: ...INDEX 1234...
Страница 1235: ......
Страница 1236: ...ECS4810 12M E072011 ST R01 149100000142A...