
C
HAPTER
14
| Security Measures
ARP Inspection
– 326 –
W
EB
I
NTERFACE
To bind an ACL to a port:
1.
Click Security, ACL.
2.
Select Configure Interface from the Step list.
3.
Select IP or MAC from the Type list.
4.
Select a port.
5.
Select the name of an ACL from the ACL list.
6.
Click Apply.
Figure 182: Binding a Port to an ACL
ARP I
NSPECTION
ARP Inspection is a security feature that validates the MAC Address
bindings for Address Resolution Protocol packets. It provides protection
against ARP traffic with invalid MAC-to-IP address bindings, which forms
the basis for certain “man-in-the-middle” attacks. This is accomplished by
intercepting all ARP requests and responses and verifying each of these
packets before the local ARP cache is updated or the packet is forwarded to
the appropriate destination. Invalid ARP packets are dropped.
ARP Inspection determines the validity of an ARP packet based on valid
IP-to-MAC address bindings stored in a trusted database – the DHCP
snooping binding database (see
"DHCP Snooping Configuration" on
). This database is built by DHCP snooping if it is enabled on
globally on the switch and on the required VLANs. ARP Inspection can also
validate ARP packets against user-configured ARP access control lists
(ACLs) for hosts with statically configured addresses (see
Содержание ES3510MA-DC
Страница 1: ...Management Guide www edge core com 8 Port Layer 2 Fast Ethernet Switch...
Страница 2: ......
Страница 4: ......
Страница 6: ...ABOUT THIS GUIDE 6...
Страница 44: ...FIGURES 44...
Страница 50: ...TABLES 50...
Страница 52: ...SECTION I Getting Started 52...
Страница 62: ...CHAPTER 1 Introduction System Defaults 62...
Страница 80: ...CHAPTER 2 Initial Switch Configuration Managing System Files 80...
Страница 82: ...SECTION II Web Configuration 82...
Страница 98: ...CHAPTER 3 Using the Web Interface Navigating the Web Browser Interface 98...
Страница 126: ...CHAPTER 4 Basic Management Tasks Resetting the System 126...
Страница 164: ...CHAPTER 5 Interface Configuration VLAN Trunking 164 Figure 57 Configuring VLAN Trunking...
Страница 202: ...CHAPTER 7 Address Table Settings Configuring MAC Address Mirroring 202...
Страница 452: ...CHAPTER 17 IP Services Displaying the DNS Cache 452...
Страница 498: ...CHAPTER 19 Using the Command Line Interface CLI Command Groups 498...
Страница 588: ...CHAPTER 22 SNMP Commands 588...
Страница 596: ...CHAPTER 23 Remote Monitoring Commands 596...
Страница 650: ...CHAPTER 24 Authentication Commands Management IP Filter 650...
Страница 738: ...CHAPTER 27 Interface Commands 738...
Страница 760: ...CHAPTER 29 Port Mirroring Commands RSPAN Mirroring Commands 760...
Страница 782: ...CHAPTER 32 Address Table Commands 782...
Страница 810: ...CHAPTER 33 Spanning Tree Commands 810...
Страница 862: ...CHAPTER 35 VLAN Commands Configuring Voice VLANs 862...
Страница 876: ...CHAPTER 36 Class of Service Commands Priority Commands Layer 3 and 4 876...
Страница 932: ...CHAPTER 38 Multicast Filtering Commands Multicast VLAN Registration 932...
Страница 956: ...CHAPTER 39 LLDP Commands 956...
Страница 1020: ...CHAPTER 42 Domain Name Service Commands 1020...
Страница 1026: ...CHAPTER 43 DHCP Commands DHCP Client 1026...
Страница 1058: ...CHAPTER 44 IP Interface Commands IPv6 Interface 1058...
Страница 1060: ...SECTION IV Appendices 1060...
Страница 1065: ...APPENDIX A Software Specifications Management Information Bases 1065 Trap RFC 1215 UDP MIB RFC 2013...
Страница 1066: ...APPENDIX A Software Specifications Management Information Bases 1066...
Страница 1088: ...COMMAND LIST 1088...
Страница 1097: ......
Страница 1098: ...ES3510MA DC E122010 ST R01 150200000251A...