ZXA10 C300 Configuration Manual (CLI)
mac-move-report :enable
mac-move-report interval:30[minutes]
mac-anti-spoofing :enable
uplink-protect
:enable
4.
(Optional) Query the MAC move log.
ZXAN#show security mac-move-log
Flag *--macMove is forbidden by system.
the total mac-move-log num:2
-------------------------------------------------------------------------
mac-address
vlan
cfgMacProtect
moveToPort
moveToIfId
moveCount
index trapFlag detector queryPort
moveFromPort
moveFromIfId trapCount
-------------------------------------------------------------------------
0002.0304.0506 100
UNNEED
inner-port_1/12/1
unknown(0)
1
1
SENDED
MP
UNNEED
inner-port_1/5/1
unknown(0)
1
-------------------------------------------------------------------------
0002.0304.0507 100
UNNEED
inner-port_1/12/2
unknown(0)
1
2
*SENDED
MP
UNNEED
inner-port_1/5/1
unknown(0)
1
– End of Steps –
14.3 Configuring the ARP Anti-Spoofing
The ARP anti-spoofing prevents the ARP spoofing on user side.
Context
The ZXA10 C300 supports user-side
anti-spoofing function, which is implemented
based on the following ARP entries:
l
The ARP entries inserted by the
module
l
The ARP entries of DHCP snooping static binding item configured by the IP source
Guard module
ARP anti-spoofing function is based on both VLAN and service port. Only when the
ARP anti-spoofing functions on both VLAN and service port are enabled, the system can
implement ARP anti-spoofing on ARP packets with the specific VLAN tag.
When receiving an ARP packet, the ZXA10 C300 compares the packet with the known
ARP entries. If the source IP address of the received ARP packet and the
exist
in the ARP table, the ZXA10 C300 checks whether the
addresses are the same. If
they are different, the ZXA10 C300 considers the packet as an ARP spoofing behavior and
discards it.
The
anti-spoofing function can be configured with up to 256
s.
14-10
SJ-20130520164529-007|2013-06-30 (R1.0)
ZTE Proprietary and Confidential
Содержание ZXA10 C300
Страница 8: ...VI SJ 20130520164529 007 2013 06 30 R1 0 ZTE Proprietary and Confidential ...
Страница 294: ...Tables This page intentionally left blank VI SJ 20130520164529 007 2013 06 30 R1 0 ZTE Proprietary and Confidential ...
Страница 301: ...Glossary VoIP Voice over Internet Protocol XIII SJ 20130520164529 007 2013 06 30 R1 0 ZTE Proprietary and Confidential ...