Operation Manual – ARP
H3C S3100 Series Ethernet Switches
Chapter 1 ARP Configuration
1-8
Operation
Command
Remarks
Enable the ARP entry
checking function (that is,
disable the switch from
learning ARP entries with
multicast MAC addresses)
arp check enable
Optional
By default, the ARP
entry checking
function is enabled.
Caution:
z
Static ARP entries are valid as long as the Ethernet switch operates normally. But
some operations, such as removing a VLAN, or removing a port from a VLAN, will
make the corresponding ARP entries invalid and therefore removed automatically.
z
As for the
arp static
command, the value of the
vlan-id
argument must be the ID of
an existing VLAN, and the port identified by the
interface-type
and
interface-number
arguments must belong to the VLAN.
z
Currently, static ARP entries cannot be configured on the ports of an aggregation
group.
1.2.2 Configuring ARP Source MAC Address Consistency Check
Table 1-5
Configure ARP Source MAC Address Consistency Check
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable ARP source MAC
address consistency
check
arp anti-attack
valid-check enable
Required
Disabled by default.
1.2.3 Configuring ARP Attack Detection
Table 1-6
Configure the ARP attack detection function
Operation
Command
Remarks
Enter system view
system-view
—
Enable DHCP snooping
dhcp-snooping
Required
By default, the DHCP
snooping function is
disabled.
Enter Ethernet port view
interface interface-type
interface-number
—