
© Copyright 2019 TRENDnet. All Rights Reserved.
TRENDnet User’s Guide
Industrial Managed Switch Series
94
ARP Inspection
Dynamic ARP inspection is a security feature which validates ARP packet in a network
by performing IP to MAC address binding inspection. Those will be stored in a trusted
database (the DHCP snooping database) before forwarding. Dynamic ARP intercepts,
logs, and discards ARP packets with invalid IP-to-MAC address bindings. This capability
protects the network from certain man-in-the-middle attacks.
Dynamic ARP inspection ensures that only valid ARP requests and responses are
relayed. The switch performs these activities:
Intercepts all ARP requests and responses on untrusted ports.
Verifies that each of these intercepted packets has a valid IP-to-MAC address
binding before it updates the local ARP cache or before it forwards the packet to
the appropriate destination.
Trusted and untrusted port
This setting is independent of the trusted and untrusted setting of the DHCP
snooping.
The Switch does not discard ARP packets on trusted ports for any reasons.
The Switch discards ARP packets on un-trusted ports if the sender’s information
in the ARP packets does not match any of the current bindings.
Normally, the trusted ports are the uplink port and the untrusted ports are
connected to subscribers.
Configuration:
Users can enable/disable the ARP Inspection on the Switch. Users also can
enable/disable the ARP Inspection on a specific VLAN. If the ARP Inspection on the
Switch is disabled, the ARP Inspection is disabled on all VLANs even some of the VLAN
ARP Inspection are enabled.
Default Settings
The ARP Inspection on the Switch is disabled.
The age time for the MAC filter is 5 minutes.
ARP Inspection is enabled in VLAN(s): None.
Port
Trusted
Port
Trusted
-----
----------
------
----------
1
no
2
no
3
no
4
no
5
no
6
no
7
no
8
no
9
no
10
no
11
no
12
no
13
no
14
no
15
no
16
no
Notices
There are a global state and per VLAN states.
When the global state is disabled, the ARP Inspection on the Switch is disabled
even per VLAN states are enabled.
When the global state is enabled, user must enable per VLAN states to enable
the ARP Inspection on the specific VLAN.
CLI Configuration
Node
Command
Description
enable
show arp-inspection
This command displays the current
ARP Inspection configurations.
configure
arp-inspection (disable | enable) This command disables/enables the
ARP Inspection function on the
switch.
configure
arp-inspection vlan VLANID
This command enables the ARP
Inspection function on a VLAN or
range of VLANs.
Содержание TI-G160WS
Страница 1: ...TRENDnet User s Guide Cover Page...
Страница 148: ......