![EtherWAN EX26262 Скачать руководство пользователя страница 119](http://html1.mh-extra.com/html/etherwan/ex26262/ex26262_management-manual_2432724119.webp)
C
HAPTER
4
| Configuring the Switch
Configuring Security
– 119 –
C
ONFIGURING
ARP
I
NSPECTION
ARP Inspection is a security feature that validates the MAC Address
bindings for Address Resolution Protocol packets. It provides protection
against ARP traffic with invalid MAC-to-IP address bindings, which forms
the basis for certain “man-in-the-middle” attacks. This is accomplished by
intercepting all ARP requests and responses and verifying each of these
packets before the local ARP cache is updated or the packet is forwarded to
the appropriate destination. Invalid ARP packets are dropped.
ARP Inspection determines the validity of an ARP packet based on valid
IP-to-MAC address bindings stored in a trusted database – the DHCP
snooping binding database (see
"Configuring DHCP Snooping"
). This
database is built by DHCP snooping if it is enabled globally on the switch
and on the required ports. ARP Inspection can also validate ARP packets
against statically configured addresses.
C
OMMAND
U
SAGE
Enabling & Disabling ARP Inspection
◆
ARP Inspection is controlled on a global and port basis.
◆
By default, ARP Inspection is disabled both globally and on all ports.
■
If ARP Inspection is globally enabled, then it becomes active only on
the ports where it has been enabled.
■
When ARP Inspection is enabled globally, all ARP request and reply
packets on inspection-enabled ports are redirected to the CPU and
their switching behavior handled by the ARP Inspection engine.
■
If ARP Inspection is disabled globally, then it becomes inactive for
all ports, including those where inspection is enabled.
■
When ARP Inspection is disabled, all ARP request and reply packets
will bypass the ARP Inspection engine and their switching behavior
will match that of all other packets.
■
Disabling and then re-enabling global ARP Inspection will not affect
the ARP Inspection configuration of any ports.
■
When ARP Inspection is disabled globally, it is still possible to
configure ARP Inspection for individual ports. These configuration
changes will only become active after ARP Inspection is enabled
globally again.
◆
ARP Inspection uses the DHCP snooping bindings database for the list
of valid IP-to-MAC address bindings.
N
OTE
:
DHCP snooping must be enabled for dynamic clients to be learned
automatically.
Содержание EX26262
Страница 1: ...Layer 2 Gigabit PoE Ethernet Switch Management Guide...
Страница 2: ......
Страница 3: ...MANAGEMENT GUIDE...
Страница 4: ......
Страница 6: ...6 ABOUT THIS GUIDE...
Страница 18: ...18 FIGURES...
Страница 20: ...20 TABLES...
Страница 22: ...22 SECTION I Getting Started...
Страница 34: ...34 SECTION II Web Configuration...
Страница 46: ...46 CHAPTER 3 Using the Web Interface Navigating the Web Browser Interface...
Страница 202: ...CHAPTER 4 Configuring the Switch Quality of Service 202 Figure 83 Configuring Port Tag Remarking Mode...
Страница 290: ...290 CHAPTER 5 Monitoring the Switch Displaying Information About Flow Sampling...
Страница 294: ...CHAPTER 6 Performing Basic Diagnostics Running Cable Diagnostics 294...
Страница 300: ...CHAPTER 7 Performing System Maintenance Managing Configuration Files 300...
Страница 302: ...302 SECTION III Appendices...
Страница 320: ...GLOSSARY 320...
Страница 325: ......
Страница 326: ......