4-10
By default, ARP detection is disabled for a VLAN.
Examples
# Enable ARP detection for VLAN 1.
<Sysname> system-view
[Sysname] vlan 1
[Sysname-Vlan1] arp detection enable
arp detection mode
Syntax
arp detection mode
{
dhcp-snooping
|
dot1x | static-bind
}
undo arp detection mode
{
dhcp-snooping
|
dot1x | static-bind
}
View
System view
Default Level
2: System level
Parameters
dhcp-snooping
: Implements ARP attack detection based on DHCP snooping entries. This mode is
mainly used to prevent source address spoofing attacks.
dot1x
: Implements ARP attack detection based on 802.1X security entries. This mode is mainly used
to prevent source address spoofing attacks.
static-bind
: Implements ARP attack detection based on static IP-to-MAC binding entries. This mode is
mainly used to prevent gateway spoofing attacks.
Description
Use the
arp detection mode
command to specify an ARP attack detection mode.
Use the
undo arp detection mode
command to cancel the specified ARP detection mode.
By default, no ARP detection mode is specified, that is, all packets are considered to be invalid.
Note that, if you specify the three modes at the same time, the system uses static IP-to-MAC bindings
first, then DHCP snooping entries, and then 802.1X security entries.
Examples
# Enable ARP detection based on both DHCP snooping entries and 802.1X security entires.
<Sysname> system-view
[Sysname] arp detection mode dhcp-snooping
[Sysname] arp detection mode dot1x
arp detection static-bind
Syntax
arp detection static-bind ip-address mac-address
Содержание E4510-48G
Страница 109: ...2 18 Sysname interface bridge aggregation 1 Sysname Bridge Aggregation1 shutdown ...
Страница 309: ...6 4 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address dhcp alloc ...
Страница 324: ...8 3 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address bootp alloc ...
Страница 530: ...2 5 Sysname mvlan 100 subvlan 10 to 15 ...
Страница 739: ...8 15 Sysname system view Sysname port security trap addresslearned ...
Страница 819: ...13 11 Sysname system view Sysname public key peer key2 import sshkey key pub ...
Страница 857: ...iii 7 Track Configuration Commands 7 1 Track Configuration Commands 7 1 display track 7 1 track nqa 7 2 ...
Страница 914: ...5 17 Sysname reset oam ...
Страница 1064: ...5 30 Slot 2 Set next configuration file successfully ...
Страница 1325: ...21 13 Examples Redirect to member 2 Sysname irf switch to 2 Sysname Slave 2 ...