2-8
z
dst-mac: Checks the target MAC address of ARP replies. If the target MAC address is all-zero,
all-one, or inconsistent with the destination MAC address in the Ethernet header, the packet is
considered invalid and discarded.
z
ip: Checks both the source and destination IP addresses in an ARP packet. The all-zero, all-one or
multicast IP addresses are considered invalid and the corresponding packets are discarded. With
this object specified, the source and destination IP addresses of ARP replies, and the source IP
address of ARP requests are checked.
Before performing the following configuration, make sure you have configured the
arp detection
enable
command.
Follow these steps to configure ARP detection based on specified objects:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Specify objects for ARP
detection
arp detection validate
{
dst-mac
|
ip
|
src-mac
} *
Required
Not specified by default.
Displaying and Maintaining ARP Detection
To do…
Use the command…
Remarks
Display the VLANs enabled
with ARP detection
display arp detection
Available in any view
Display the ARP detection
statistics
display arp detection statistics
[
interface
interface-type interface-number
]
Available in any view
Clear the ARP detection
statistics
reset arp detection statistics
[
interface
interface-type interface-number
]
Available in user view
ARP Detection Configuration Example
Network requirements
As shown in
Figure 2-2
, enable DHCP snooping on Switch A. Enable ARP detection for VLAN 10 to
allow only packets from valid clients to pass. Configure Host A and Host B as DHCP clients.
Содержание S5810 Series
Страница 307: ...ii Configured Multicast Group Policy Fails to Take Effect 1 32...
Страница 648: ...1 8 Return to the upper directory Sysname cd Display the current working directory Sysname pwd flash...
Страница 812: ...1 7 Role Slave Sysname stack_3 DeviceD Device type S5810 50S MAC address 000f e200 1003...