General Security Measures
3-139
3
not selected, the switch first performs ARP Inspection and then validation
against the DHCP Snooping Bindings database. (Default: Disabled)
•
ARP Inspection Validation
– Enables extended ARP Inspection Validation if any
of the following options are enabled. (Default: Disabled)
-
Dst-MAC
– Validates the destination MAC address in the Ethernet header
against the target MAC address in the body of ARP responses.
-
IP
– Checks the ARP body for invalid and unexpected IP addresses. Sender IP
addresses are checked in all ARP requests and responses, while target IP
addresses are checked only in ARP responses.
-
Src-MAC
– Validates the source MAC address in the Ethernet header against
the sender MAC address in the ARP body. This check is performed on both ARP
requests and responses.
•
ARP Inspection Log
– Configures ARP Inspection logging parameters.
-
Message Number
– The maximum number of entries saved in a log message.
(Range: 0-256; Default: 5)
-
Interval
– The interval at which log messages are sent. (Range: 0-86400
seconds; Default: 1 second)
•
Port
– Port identifier. (Range: 1-28/52; Default: 1)
•
Trust Status
– Configures the port as trusted or untrusted. (Default: Untrusted)
•
ARP Inspection Packet Rate Limit
– Limits the rate of accepted ARP packets on
untrusted ports.
-
Rate
– The maximum number of ARP packets that can be processed by CPU
per second. (Range: 0-2048; Default: 15)
-
None
– Sets no limit on the number of ARP packets that can be processed by
the CPU.
Содержание 6152PL2 FICHE
Страница 2: ......
Страница 6: ...vi ...
Страница 8: ...viii ...
Страница 32: ...Tables xxxii ...
Страница 38: ...Figures xxxviii ...
Страница 56: ...Initial Configuration 2 10 2 ...
Страница 378: ...Configuring the Switch 3 322 3 ...
Страница 651: ...Address Table Commands 4 273 4 Example Console show mac address table aging time Aging time 100 sec Console ...
Страница 817: ......
Страница 818: ...SMC6128PL2 SMC6152PL2 149100000007A R01 ...