EasyManuals Logo

Edge-Core ECS2100-28T Reference Guide

Edge-Core ECS2100-28T
725 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #305 background imageLoading...
Page #305 background image
Chapter 9
| General Security Measures
ARP Inspection
– 305
interface - Specifies a port interface.
ethernet
unit/port
unit - Unit identifier. (Range: 1)
port - Port number. (Range: 1-10/28)
Command Mode
Privileged Exec
Example
Console#show ip source-guard binding
MAC Address IP Address Type VLAN Interface
----------------- --------------- -------------- --------- ---------
00-10-b5-f4-d0-01 10.2.44.96 static-acl 1 Eth 1/1
Console#
ARP Inspection
ARP Inspection validates the MAC-to-IP address bindings in Address Resolution
Protocol (ARP) packets. It protects against ARP traffic with invalid address bindings,
which forms the basis for certain “man-in-the-middle” attacks. This is accomplished
by intercepting all ARP requests and responses and verifying each of these packets
before the local ARP cache is updated or the packet is forwarded to the appropriate
destination, dropping any invalid ARP packets.
ARP Inspection determines the validity of an ARP packet based on valid IP-to-MAC
address bindings stored in a trusted database – the DHCP snooping binding
database. ARP Inspection can also validate ARP packets against user-configured
ARP access control lists (ACLs) for hosts with statically configured IP addresses.
This section describes commands used to configure ARP Inspection.
Table 59: ARP Inspection Commands
Command Function Mode
ip arp inspection Enables ARP Inspection globally on the switch GC
ip arp inspection filter Specifies an ARP ACL to apply to one or more VLANs GC
ip arp inspection log-buffer
logs
Sets the maximum number of entries saved in a log
message, and the rate at these messages are sent
GC
ip arp inspection validate Specifies additional validation of address components in
an ARP packet
GC
ip arp inspection vlan Enables ARP Inspection for a specified VLAN or range of
VLANs
GC
ip arp inspection limit Sets a rate limit for the ARP packets received on a port IC
ip arp inspection trust Sets a port as trusted, and thus exempted from ARP
Inspection
IC

Table of Contents

Other manuals for Edge-Core ECS2100-28T

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Edge-Core ECS2100-28T and is the answer not in the manual?

Edge-Core ECS2100-28T Specifications

General IconGeneral
BrandEdge-Core
ModelECS2100-28T
CategorySwitch
LanguageEnglish

Related product manuals