Raisecom
ISCOM2600G-HI (A) Series Configuration Guide
10 Security
Raisecom Proprietary and Confidential
Copyright © Raisecom Technology Co., Ltd.
412
The system provides auto-recovery and supports configuring the recovery time. The
interfaces, where the number of received ARP packets is greater than the threshold, will
recover to normal Rx/Tx status automatically after the recovery time expires.
Dynamic ARP inspection can also protect the specified VLAN. After the protection VLAN is
configured, the ARP packets in specified VLAN on an untrusted interface will be protected.
Only the ARP packets, which meet binding table rules, are permitted to pass. Other packets
are discarded.
10.3.2 Preparing for configurations
Scenario
Dynamic ARP inspection is used to prevent common ARP spoofing attacks on the network,
which isolates ARP packets from unsafe sources. Whether to trust ARP packets depend on the
trusting status of an interface while ARP packets meet requirements depends on the ARP
binding table.
Prerequisite
Enable DHCP Snooping if there is a DHCP user.
10.3.3 Default configurations of dynamic ARP inspection
Default configurations of dynamic ARP inspection are as below.
Function
Default value
Dynamic ARP inspection interface trust status
Untrusted
Dynamic ARP inspection static binding
Disable
Dynamic ARP inspection dynamic binding
Disable
Dynamic ARP inspection static binding table
N/A
Dynamic ARP inspection protection VLAN
All VLANs
Interface rate limiting on ARP packets
60 pps
10.3.4 Configuring trusted interfaces of dynamic ARP inspection
Configure trusted interfaces of dynamic ARP inspection for the ISCOM2600G-HI series
switch as below.
Step
Command
Description
1
Raisecom#config
Enter global configuration mode.
2
Raisecom(config)#interface
interface-type interface-
number
Enter physical layer interface configuration
mode.