© Copyright Lenovo 2018
279
Chapter 18. Dynamic ARP Inspection
Address
Resolution
Protocol
(ARP)
provides
IP
communication
within
a
Layer
2
broadcast
domain
by
mapping
an
IP
address
to
a
MAC
address.
Network
devices
maintain
this
mapping
in
a
cache
that
they
consult
when
forwarding
packets
to
other
devices.
If
the
ARP
cache
does
not
contain
an
entry
for
the
destination
device,
the
host
broadcasts
an
ARP
request
for
that
device
ʹ
s
address
and
stores
the
response
in
the
cache.
Understanding ARP Spoofing Attacks
ARP
spoofing
(also
referred
to
as
ARP
cache
poisoning)
is
one
way
to
initiate
man
‐
in
‐
the
‐
middle
attacks.
A
malicious
user
could
poison
the
ARP
caches
of
connected
systems
(hosts,
switches,
routers)
by
sending
forged
ARP
responses
and
could
intercept
traffic
intended
for
other
hosts
on
the
LAN
segment.
For
example,
in
,
the
attacker
(Host
C)
can
send
an
ARP
Reply
to
Host
A
pretending
to
be
Host
B.
As
a
result,
Host
A
populates
its
ARP
cache
with
a
poisoned
entry
having
IP
address
IB
and
MAC
address
MC.
Host
A
will
use
the
MAC
address
MC
as
the
destination
MAC
address
for
traffic
intended
for
Host
B.
Host
C
then
intercepts
that
traffic.
Because
Host
C
knows
the
true
MAC
addresses
associated
with
Host
B,
it
forwards
the
intercepted
traffic
to
that
host
by
using
the
correct
MAC
address
as
the
destination,
keeping
the
appearance
of
regular
behavior.
Figure 28.
ARP
Cache
Poisoning
Understanding DAI
Dynamic
ARP
Inspection
is
a
security
feature
that
lets
the
switch
intercept
and
examine
all
ARP
request
and
response
packets
in
a
subnet,
discarding
those
packets
with
invalid
IP
to
MAC
address
bindings.
This
capability
protects
the
network
from
man
‐
in
‐
the
‐
middle
attacks.
A
switch
on
which
ARP
Inspection
is
configured
does
the
following:
Intercepts
all
ARP
requests
and
responses
on
untrusted
ports.
Verifies
that
each
of
these
intercepted
packets
has
a
valid
IP/MAC/VLAN/port
binding
before
updating
the
local
ARP
cache
or
before
forwarding
the
packet
to
the
appropriate
destination.
Host A
(IA, MA)
Host B
(IB, MB)
Host C (man-in-the-middle)
(IC, MC)
A
B
C
Содержание ThinkSystem NE2552E
Страница 27: ... Copyright Lenovo 2018 27 Part 1 Getting Started ...
Страница 28: ...28 NE2552E Application Guide for ENOS 8 4 ...
Страница 70: ...70 NE2552E Application Guide for ENOS 8 4 ...
Страница 85: ... Copyright Lenovo 2018 85 Part 2 Securing the Switch ...
Страница 86: ...86 NE2552E Application Guide for ENOS 8 4 ...
Страница 112: ...112 NE2552E Application Guide for ENOS 8 4 ...
Страница 134: ...134 NE2552E Application Guide for ENOS 8 4 ...
Страница 154: ...154 NE2552E Application Guide for ENOS 8 4 ...
Страница 194: ...194 NE2552E Application Guide for ENOS 8 4 ...
Страница 218: ...218 NE2552E Application Guide for ENOS 8 4 ...
Страница 234: ...234 NE2552E Application Guide for ENOS 8 4 ...
Страница 238: ...238 NE2552E Application Guide for ENOS 8 4 ...
Страница 239: ... Copyright Lenovo 2018 239 Part 4 Advanced Switching Features ...
Страница 240: ...240 NE2552E Application Guide for ENOS 8 4 ...
Страница 242: ...242 NE2552E Application Guide for ENOS 8 4 ...
Страница 278: ...278 NE2552E Application Guide for ENOS 8 4 ...
Страница 284: ...284 NE2552E Application Guide for ENOS 8 4 ...
Страница 314: ...314 NE2552E Application Guide for ENOS 8 4 ...
Страница 338: ...338 NE2552E Application Guide for ENOS 8 4 ...
Страница 374: ...374 NE2552E Application Guide for ENOS 8 4 ...
Страница 388: ...388 NE2552E Application Guide for ENOS 8 4 ...
Страница 418: ...418 NE2552E Application Guide for ENOS 8 4 ...
Страница 430: ...430 NE2552E Application Guide for ENOS 8 4 ...
Страница 432: ...432 NE2552E Application Guide for ENOS 8 4 ...
Страница 436: ...436 NE2552E Application Guide for ENOS 8 4 ...
Страница 460: ...460 NE2552E Application Guide for ENOS 8 4 ...
Страница 461: ... Copyright Lenovo 2018 461 Part 7 Network Management ...
Страница 462: ...462 NE2552E Application Guide for ENOS 8 4 ...
Страница 476: ...476 NE2552E Application Guide for ENOS 8 4 ...
Страница 498: ...498 NE2552E Application Guide for ENOS 8 4 ...
Страница 520: ...520 NE2552E Application Guide for ENOS 8 4 ...
Страница 534: ...534 NE2552E Application Guide for ENOS 8 4 ...
Страница 536: ...536 NE2552E Application Guide for ENOS 8 4 ...
Страница 544: ...544 NE2552E Application Guide for ENOS 8 4 ...
Страница 549: ... Copyright Lenovo 2018 549 Part 9 Appendices ...
Страница 550: ...550 NE2552E Application Guide for ENOS 8 4 ...
Страница 566: ...566 NE2552E Application Guide for ENOS 8 4 ...
Страница 572: ...572 NE2552E Application Guide for ENOS 8 4 ...
Страница 573: ......
Страница 574: ...Part Number 01KN246 Printed in USA IP P N 01KN246 ...