1
1
ARP and IP Attack Defense Configuration
ARP Packet Filtering Based on Gateway’s Address
Introduction
According to the ARP design, after receiving an ARP packet with the target IP address being that of the
receiving interface, a device adds the IP-to-MAC mapping of the sender into its ARP mapping table
even if the MAC address is not requested by itself. This can reduce the ARP traffic in the network, but it
also makes ARP spoofing possible.
The most common ARP attack on campus networks is the gateway spoofing attack. An attacker sends
an ARP packet with the gateway’s IP address and a fake MAC address, and then a receiving host
updates the IP-to-MAC binding of the gateway. As a result, the traffic sent from the host to the gateway
will be redirected to the fake MAC address, and the client will be unable to access the external network.
Figure 1-1
Gateway spoofing attack
To prevent gateway spoofing attacks, S3100-EI series Ethernet switches can filter ARP packets based
on the gateway’s address.
1) You can bind the gateway’s IP address to the downstream port (directly connected to hosts) of the
switch. After that, the port will discard ARP packets with the gateway’s IP address as the sender IP
address, and permit other ARP packets to pass.
2) You can also bind the IP and MAC addresses of the gateway to the cascaded port or upstream port
of the access switch. After that, the port will discard ARP packets with the sender IP address as the
gateway’s IP address but with the sender MAC address different from the gateway’s MAC address,
and permit other ARP packets to pass.
Configuring ARP Packet Filtering
Содержание S3100 Series
Страница 12: ...10 You can e mail your comments about product documentation to info h3c com We appreciate your comments...
Страница 74: ...7 7 Sysname ip http acl 2030...
Страница 270: ...1 51 Sysname GigabitEthernet1 0 1 port trunk permit vlan all...
Страница 287: ...1 14 the interface on which the packet actually arrived The RPF check succeeds and the packet is forwarded...
Страница 579: ...ii Configuration Example 2 4 QoS Profile Configuration Example 2 4...
Страница 713: ...1 22 Total associations 1...
Страница 823: ...1 16...
Страница 1054: ...i Table of Contents Appendix A Acronyms A 1...