467
Configure user validity check before you configure ARP restricted forwarding.
To enable ARP restricted forwarding:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter VLAN view.
vlan vlan-id
N/A
3.
Enable ARP restricted forwarding.
arp restricted-forwarding
enable
By default, ARP restricted
forwarding is disabled.
Enabling ARP attack detection logging
The ARP attack detection logging feature enables a device to generate ARP attack detection log
messages when illegal ARP packets are detected. An ARP attack detection log message contains
the following information:
1.
Receiving interface of the ARP packets.
2.
Sender IP address.
3.
Total number of dropped ARP packets.
To enable ARP attack detection logging:
Step Command Remarks
1.
Enter system view.
system-view
N/A
2.
Enable ARP attack
detection logging.
arp detection log enable
By default, ARP attack detection
logging is disabled.
Displaying and maintaining ARP attack detection
Execute
display
commands in any view and
reset
commands in user view.
Task Command
Display the VLANs enabled with
ARP attack detection.
display arp detection
Display the ARP attack detection
statistics.
display arp detection statistics
[
interface
interface-type
interface-number
]
Clear the ARP attack detection
statistics.
reset arp detection statistics
[
interface interface-type
interface-number
]
User validity check configuration example
Network requirements
As shown in
, configure Device B to perform user validity check based on 802.1X security
entries for connected hosts.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...