
1-7
z
When most clients acquire IP addresses through DHCP and some clients use static IP addresses,
you need to enable DHCP snooping and configure static IP binding entries on the switch. These
functions can cooperate with ARP attack detection to check the validity of packets. For more
information about DHCP snooping, refer to
DHCP Operation
in this manual
.
z
Generally, the uplink port of a switch is configured as a trusted port.
z
Before enabling ARP restricted forwarding, make sure you have enabled ARP attack detection and
configured ARP trusted ports.
z
You are not recommended to configure ARP attack detection on the ports of an aggregation group.
z
Currently, the VLAN ID of an IP-to-MAC binding configured on a port of an S5100-SI/EI series
Ethernet switch is the same as the default VLAN ID of the port. If the VLAN tag of an ARP packet is
different from the default VLAN ID of the receiving port, the ARP packet cannot pass the ARP
attack detection based on the IP-to-MAC bindings.
Configuring Gratuitous ARP
Follow these steps to configure gratuitous ARP:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable the gratuitous ARP
packet learning function
gratuitous-arp-learning
enable
Optional
Enabled by default.
The sending of gratuitous ARP packets is enabled as long as an S5100-SI/EI switch operates. No
command is needed for enabling this function. That is, the device sends gratuitous ARP packets
whenever a VLAN interface is enabled (such as when a link is enabled or an IP address is configured
for the VLAN interface) or whenever the IP address of a VLAN interface is changed.
Displaying and Debugging ARP
To do…
Use the command…
Remarks
Display specific ARP mapping
table entries
display arp
[
static
|
dynamic
|
ip-address
]
Display the ARP mapping
entries related to a specified
string in a specified way
display arp
[
dynamic
|
static
]
|
{
begin
|
include
|
exclude
}
regular-expression
Display the number of the ARP
entries of a specified type
display arp count
[
[
dynamic
|
static
]
[ |
{
begin
|
include
|
exclude
}
regular-expression
] |
ip-address
]
Available in any view
Содержание H3C S5100-SI
Страница 129: ...1 10...
Страница 522: ...ii...
Страница 701: ...3 2...
Страница 797: ...1 20 0 00 packet loss round trip min avg max 50 60 70 ms...
Страница 827: ...i Table of Contents 1 Acronyms 1 1...