EasyManuals Logo

Cisco SG350-28P Administration Guide

Cisco SG350-28P
762 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #504 background imageLoading...
Page #504 background image
Security
ARP Inspection
Cisco 350, 350X and 550X Series Managed Switches, Firmware Release 2.4, ver 0.4 361
17
Properties
Interfaces Settings
Interfaces Settings
ARP Access Control
ARP Access Control Rules
VLAN Settings
How ARP Prevents Cache Poisoning
The ARP inspection feature relates to interfaces as either trusted or untrusted (see Interfaces
Settings page).
Interfaces are classified by the user as follows:
Trusted Packets are not inspected.
Untrusted —Packets are inspected as described above.
ARP inspection is performed only on untrusted interfaces. ARP packets that are received on
the trusted interface are simply forwarded.
Upon packet arrival on untrusted interfaces the following logic is implemented:
Search the ARP access control rules for the packet's IP/MAC addresses. If the IP
address is found and the MAC address in the list matches the packet's MAC address,
then the packet is valid; otherwise it is not.
If the packet's IP address was not found, and DHCP Snooping is enabled for the
packet’s VLAN, search the DHCP Snooping Binding database for the packet's <VLAN
- IP address> pair. If the <VLAN - IP address> pair was found, and the MAC address
and the interface in the database match the packet's MAC address and ingress
interface, the packet is valid.
If the packet's IP address was not found in the ARP access control rules or in the
DHCP Snooping Binding database the packet is invalid and is dropped. A SYSLOG
message is generated.
If a packet is valid, it is forwarded and the ARP cache is updated.

Table of Contents

Other manuals for Cisco SG350-28P

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco SG350-28P and is the answer not in the manual?

Cisco SG350-28P Specifications

General IconGeneral
ModelSG350-28P
CategorySwitch
Ports28
PoE Ports24
PoE Budget195W
Switching Capacity56 Gbps
Forwarding Rate41.67 Mpps
LayerLayer 3
Rack MountableYes
Gigabit Ethernet Ports28
MAC Address Table Size16K
Power SupplyInternal
Jumbo Frame SupportYes
Dimensions (W x D x H)440 x 257 x 44 mm
Operating Temperature0°C to 40°C
Storage Temperature-20°C to 70°C
Humidity10% to 90% non-condensing

Related product manuals