475
Figure 136 Network diagram
Configuration procedure
# Configure ARP filtering on Device B.
<DeviceB> system-view
[DeviceB] interface ten-gigabitethernet 1/0/1
[DeviceB-Ten-GigabitEthernet1/0/1] arp filter binding 10.1.1.2 000f-e349-1233
[DeviceB-Ten-GigabitEthernet1/0/1] quit
[DeviceB] interface ten-gigabitethernet 1/0/2
[DeviceB-Ten-GigabitEthernet1/0/2] arp filter binding 10.1.1.3 000f-e349-1234
Verifying the configuration
# Verify that Ten-GigabitEthernet 1/0/1 permits ARP packets from Host A and discards other ARP
packets.
# Verify that Ten-GigabitEthernet 1/0/2 permits ARP packets from Host B and discards other ARP
packets.
Configuring ARP sender IP address checking
This feature allows a gateway to check the sender IP address of an ARP packet in a VLAN before
ARP learning. If the sender IP address is within the allowed IP address range, the gateway continues
ARP learning. If the sender IP address is out of the range, the gateway determines the ARP packet
as an attack packet and discards it.
When you configure the ARP sender IP address checking feature in a VLAN, follow these restrictions
and guidelines:
•
If the VLAN is a sub-VLAN and is associated with a super VLAN, configure this checking feature
only in the sub-VLAN.
•
If Layer 3 communication is configured between the secondary VLANs associated with a
primary VLAN, configure this feature in the primary VLAN. If Layer 3 communication is not
configured between the secondary VLANs associated with a primary VLAN, configure this
feature in the intended VLAN.
To configure the ARP sender IP address checking feature:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
Device A
Device B
Host A
Host B
XGE1/0/1
XGE1/0/3
XGE1/0/2
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...