Chapter 9
| General Security Measures
ARP Inspection
– 297 –
00-10-b5-f4-d0-01 10.2.44.96 static-acl 1 Eth 1/1
Console#
ARP Inspection
ARP Inspection validates the MAC-to-IP address bindings in Address
Resolution Protocol (ARP) packets. It protects against ARP traffic with invalid
address bindings, which forms the basis for certain “man-in-the-middle”
attacks. This is accomplished by intercepting all ARP requests and responses
and verifying each of these packets before the local ARP cache is updated or
the packet is forwarded to the appropriate destination, dropping any invalid
ARP packets.
ARP Inspection determines the validity of an ARP packet based on valid IP-to-
MAC address bindings stored in a trusted database – the DHCP snooping
binding database. ARP Inspection can also validate ARP packets against
user-configured ARP access control lists (ACLs) for hosts with statically
configured IP addresses.
This section describes commands used to configure ARP Inspection.
Table 58: ARP Inspection Commands
Command
Function
Mode
Enables ARP Inspection globally on the switch
GC
Specifies an ARP ACL to apply to one or more VLANs GC
Sets the maximum number of entries saved in a log
message, and the rate at these messages are sent
GC
Specifies additional validation of address
components in an ARP packet
GC
Enables ARP Inspection for a specified VLAN or
range of VLANs
GC
Sets a rate limit for the ARP packets received on a
port
IC
Sets a port as trusted, and thus exempted from ARP
Inspection
IC
Displays the global configuration settings for ARP
Inspection
PE
Shows the trust status and inspection rate limit for
ports
PE
Shows information about entries stored in the log,
including the associated VLAN, port, and address
components
PE
Shows statistics about the number of ARP packets
processed, or dropped for various reasons
PE
Shows configuration setting for VLANs, including
ARP Inspection status, the ARP ACL name, and if the
DHCP Snooping database is used after ACL
validation is completed
PE
Содержание SC30010
Страница 1: ...C 300 Series Gigabit Managed Switch CLI Reference Guide SOFTWARE RELEASE V1 1 10 171 www signamax com ...
Страница 2: ...CLI Reference Guide SC30010 C 300 48 Port Gigabit Managed Switch E122017 KS R01 ...
Страница 482: ...Chapter 19 Class of Service Commands Priority Commands Layer 3 and 4 482 ...
Страница 670: ......
Страница 671: ...E122017 KS R01 ...