EasyManua.ls Logo

Enterasys SecureStack C2 C2G170-24

Enterasys SecureStack C2 C2G170-24
698 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
set arpinspection trust
SecureStack C2 Configuration Guide 17-21
DAIusestheDHCPsnoopingbindingsdatabasetoverifythatthesenderMACaddressandthe
sourceIPaddressareavalidpairinthedatabase.ARPpacketswhosesenderMACaddressand
senderIPaddressdonotmatchanentryinthedatabasearedropped.
Ifloggingisenabled,invalid
ARPpacketsarealsologged.
Example
ThisexampleenablesDAIonVLANs2through5andalsoenablesloggingofinvalidARPpackets
onthoseVLANs.
C2(su)->set arpinspection vlan 2-5 logging
set arpinspection trust
UsethiscommandtoenableordisableaportasadynamicARPinspectiontrustedport.
Syntax
set arpinspection trust port port-string {enable | disable}
Parameters
Defaults
Bydefault,allphysicalportsandLAGsareuntrusted.
Mode
Switchcommand,readwrite.
Usage
Individualinterfacesareconfiguredas trustedoruntrusted.ThetrustconfigurationforDAIis
independentofthetrustconfigurationforDHCPsnooping.Atrustedportisaportthenetwork
administratordoesnotconsidertobeasecuritythreat.Anuntrustedportisonewhichcould
potentiallybeusedtolaunch
anetworkattack.
DAIconsidersallphysicalportsandLAGsuntrustedbydefault.Packetsarrivingontrusted
interfacesbypassallDAIvalidationchecks.
Example
Thisexampleenablesportge.1.1astrustedforDAI.
C2(su)->set arpinspection trust port ge.1.1 enable
portstring SpecifiestheportorportstobeenabledordisabledasDAItrusted
ports.TheportscanbephysicalportsorLAGsthataremembersofa
VLAN.
enable|disable EnablesordisablesthespecifiedportsastrustedforDAI.

Table of Contents

Other manuals for Enterasys SecureStack C2 C2G170-24

Related product manuals