![Quanta Computer QuantaMesh Скачать руководство пользователя страница 522](http://html1.mh-extra.com/html/quanta-computer/quantamesh/quantamesh_user-manual_770072522.webp)
UANTA COMPUTER INC.
Layer 2/3/4 Managed Switch
QuantaMesh | Switching Commands
522
5.19 Dynamic ARP Inspection (DAI) Command
Dynamic ARP Inspection (DAI) is a security feature that rejects invalid and malicious ARP packets. DAI
prevents a class of man-in-the-middle attacks, where an unfriendly station intercepts traffic for other
stations by poisoning the ARP caches of its unsuspecting neighbors. The miscreant sends ARP
requests or responses mapping another station's IP address to its own MAC address.
To prevent ARP poisoning attacks, a switch must ensure that only valid ARP requests and responses
are relayed. DAI prevents these attacks by intercepting all ARP requests and responses. Each of these
intercepted packets is verified for valid MAC address to IP address bindings before the local ARP cache
is updated or the packet is forwarded to the appropriate destination. Invalid ARP packets are dropped.
DAI determines the validity of an ARP packet based on valid MAC address to IP address bindings stored
in a trusted database. This database is built at runtime by DHCP snooping, provided this feature is
enabled on VLANs and on the switch. DAI relies on DHCP snooping. DHCP snooping listens to DHCP
message exchanges and builds a binding database of valid {MAC address, IP address, VLAN, and
interface} tuples. In addition, in order to handle hosts that use statically configured IP addresses, DAI
can also validate ARP packets against user-configured ARP ACLs.
When DAI is enabled, the switch drops ARP packets whose sender MAC address and sender IP
address do not match an entry in the DHCP snooping bindings database. You can optionally configure
additional ARP packet validation.
Содержание QuantaMesh
Страница 17: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Introduction 17 ...
Страница 224: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Switching Commands 224 ...
Страница 226: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Switching Commands 226 ...
Страница 229: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Switching Commands 229 ...
Страница 411: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Switching Commands 411 ...
Страница 514: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Switching Commands 514 Global Config ...
Страница 626: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Switching Commands 626 Command Mode Global Config ...
Страница 631: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Switching Commands 631 ...
Страница 636: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Switching Commands 636 ...
Страница 644: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh Switching Commands 644 Global Config ...
Страница 862: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh IP Multicast Commands 862 ...
Страница 881: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh IP Multicast Commands 881 None Command Mode Global Config ...
Страница 912: ...UANTA COMPUTER INC Layer 2 3 4 Managed Switch QuantaMesh IPv6 Commands 912 8 3 1 8 ...