–
324
–
Chapter 12
| Security Measures
ARP Inspection
Figure 202: Showing the IPv4 Source Guard Binding Table
ARP Inspection
ARP Inspection is a security feature that validates the MAC Address bindings for
Address Resolution Protocol packets. It provides protection against ARP traffic with
invalid MAC-to-
IP address bindings, which forms the basis for certain “man
-in-the-
middle”
attacks. This is accomplished by intercepting all ARP requests and
responses and verifying each of these packets before the local ARP cache is
updated or the packet is forwarded to the appropriate destination. Invalid ARP
packets are dropped.
ARP Inspection determines the validity of an ARP packet based on valid IP-to-MAC
address bindings stored in a trusted database
–
the DHCP snooping binding
database (see
“DHCP Snooping Global Configuration” on page 313
). This database
is built by DHCP snooping if it is enabled on globally on the switch and on the
required VLANs. ARP Inspection can also validate ARP packets against user-
configured ARP access control lists (ACLs) for hosts with statically configured
addresses (see
Command Usage
Enabling & Disabling ARP Inspection
◆
ARP Inspection is controlled on a global and VLAN basis.
◆
By default, ARP Inspection is disabled both globally and on all VLANs.
■
If ARP Inspection is globally enabled, then it becomes active only on the
VLANs where it has been enabled.
■
When ARP Inspection is enabled globally, all ARP request and reply packets
on inspection-enabled VLANs are redirected to the CPU and their switching
behavior handled by the ARP Inspection engine.
Содержание GEL-5261
Страница 14: ...14 Contents Glossary 551 Index 559...
Страница 26: ...26 Figures...
Страница 30: ...30 Section I Getting Started...
Страница 42: ...42 Section II Web Configuration IP Services on page 527...
Страница 45: ...Chapter 2 Using the Web Interface NavigatingtheWebBrowserInterface 45 Figure 1 Dashboard...
Страница 62: ...62 Chapter 2 Using the Web Interface NavigatingtheWebBrowserInterface...
Страница 180: ...Chapter 6 Address Table Settings Issuing MAC Address Traps 180...
Страница 208: ...Chapter 8 Congestion Control Storm Control 208 Figure 121 Configuring Storm Control...
Страница 218: ...218 Chapter 9 Class of Service Layer 3 4 Priority Settings Figure 128 Configuring DSCP to Queue Mapping...
Страница 228: ...228 Chapter 10 Quality of Service Attaching a Policy Map to a Port...
Страница 332: ...Chapter 12 Security Measures ARP Inspection 332 Figure 207 Displaying the ARP Inspection Log...
Страница 436: ...Chapter 13 Basic Administration Protocols LBD Configuration 436...
Страница 488: ...488 Chapter 14 Multicast Filtering Filtering MLD Query Packets on an Interface...
Страница 498: ...Chapter 15 IP Tools Address Resolution Protocol 498...
Страница 517: ...517 Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 interface...
Страница 542: ...540 Section III Appendices...
Страница 560: ...Glossary 558...
Страница 569: ...567 Index web interface access requirements 43 configuration buttons 46 menu list 47 panel display 46...
Страница 570: ...568 Index E062017 ST R01...