231
To do…
Use the command…
Remarks
4.
Return to system view.
quit
—
5.
Enter Layer 2 Ethernet
interface/Layer 2
aggregate interface
view.
interface
interface-type
interface-number
—
6.
Configure the port as a
trusted port on which
ARP detection does not
apply.
arp detection trust
Optional.
The port is an untrusted port by default.
Configuring ARP detection based on specified objects
With this feature configured, the device permits the ARP packets received from an ARP trusted port and
checks the ARP packets received from an ARP untrusted port. You can specify objects in the ARP packets
to be checked by using the following options:
•
src-mac
—Checks whether the sender MAC address of an ARP packet is identical to the source
MAC address in the Ethernet header. If they are identical, the packet is forwarded; otherwise, the
packet is discarded.
•
dst-mac
—Checks the target MAC address of ARP replies. If the target MAC address is all-zero, all-
one, or inconsistent with the destination MAC address in the Ethernet header, the packet is
considered invalid and discarded.
•
ip
—Checks the sender and target IP addresses in an ARP packet. Any all-zero, all-one or multicast
IP addresses are considered invalid, and the corresponding packets are discarded. With this object
specified, the sender and target IP addresses of ARP replies and the source IP address of ARP
requests are checked.
To configure ARP detection based on specified objects:
To do…
Use the command…
Remarks
1.
Enter system view.
system-view
—
2.
Enter VLAN view.
vlan
vlan-id
—
3.
Enable ARP detection for the
VLAN.
arp detection enable
Required.
Disabled by default.
4.
Return to system view.
quit
—
5.
Specify the objects to be
checked.
arp detection validate
{
dst-mac
|
ip
|
src-mac
} *
Required.
Disabled by default.
6.
Enter Layer 2 Ethernet
port/Layer 2 aggregate
interface view.
interface
interface-type interface-
number
—
7.
Configure the port as a
trusted port on which ARP
detection does not apply.
arp detection trust
Optional.
The port is an untrusted port by
default.
Содержание A5830 Series
Страница 207: ...199 Figure 62 SFTP client interface ...