Configuring Arp Packet Validity Check - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

To configure user validity check:
Step
1.
Enter system view.
2.
Enter VLAN view.
3.
Enable ARP detection.
4.
Return to system view.
5.
Enter Layer-2 Ethernet interface
view or Layer aggregate
interface view.
6.
Configure the port as a trusted
port that is excluded from ARP
detection.
At least a static IP source guard binding entry, a DHCP snooping entry, or an 802.1X security entry must
be available to perform user validity check. Otherwise, ARP packets received from ARP untrusted ports
will be discarded, except for the ARP packets whose sender MAC address is an OUI MAC address when
voice VLAN is enabled.
You must specify a VLAN for an IP source guard binding entry; otherwise, no ARP packets can match the
IP source guard binding entry.

Configuring ARP packet validity check

Perform this task to enable validity check for ARP packets received on untrusted ports and specify the
following objects to be checked.
src-mac—Checks whether the sender MAC address in the message body is identical to the source
MAC address in the Ethernet header. If they are identical, the packet is forwarded. Otherwise, the
packet is discarded.
dst-mac—Checks the target MAC address of ARP replies. If the target MAC address is all-zero,
all-one, or inconsistent with the destination MAC address in the Ethernet header, the packet is
considered invalid and discarded.
ip—Checks the sender and target IP addresses of ARP replies, and the sender IP address of ARP
requests. All-zero, all-one, or multicast IP addresses are considered invalid and the corresponding
packets are discarded.
To configure ARP packet validity check:
Step
1.
Enter system view.
2.
Enter VLAN view.
3.
Enable ARP detection.
4.
Return to system view.
5.
Enable ARP packet validity check
and specify the objects to be
checked.
Command
system-view
vlan vlan-id
arp detection enable
quit
interface interface-type interface-number
arp detection trust
Command
system-view
vlan vlan-id
arp detection enable
quit
arp detection validate { dst-mac | ip |
src-mac } *
258
Remarks
N/A
N/A
Disabled by default.
N/A
N/A
Optional.
A port is an untrusted
port by default.
Remarks
N/A
N/A
Disabled by default.
N/A
Disabled by default.

Advertisement

Table of Contents
loading

Table of Contents