EasyManuals Logo

HP PROCURVE 2910AL User Manual

HP PROCURVE 2910AL
594 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #404 background imageLoading...
Page #404 background image
Configuring Advanced Threat Protection
Dynamic ARP Protection
Verifies IP-to-MAC address bindings on untrusted ports with the informa-
tion stored in the lease database maintained by DHCP snooping and user-
configured static bindings (in non-DHCP environments):
If a binding is valid, the switch updates its local ARP cache and
forwards the packet.
If a binding is invalid, the switch drops the packet, preventing other
network devices from receiving the invalid IP-to-MAC information.
DHCP snooping intercepts and examines DHCP packets received on
switch ports before forwarding the packets. DHCP packets are checked
against a database of DHCP binding information. Each binding consists
of a client MAC address, port number, VLAN identifier, leased IP address,
and lease time. The DHCP binding database is used to validate packets by
other security features on the switch. For more information, refer to
“DHCP Snooping” in the Access Security Guide.
If you have already enabled DHCP snooping on a switch, you may also
want to add static IP-to-MAC address bindings to the DHCP snooping
database so that ARP packets from devices that have been assigned static
IP addresses are also verified.
Supports additional checks to verify source MAC address, destination
MAC address, and IP address.
ARP packets that contain invalid IP addresses or MAC addresses in their
body that do not match the addresses in the Ethernet header are dropped.
When dynamic ARP protection is enabled, only ARP request and reply packets
with valid IP-to-MAC address bindings in their packet header are relayed and
used to update the ARP cache.
Dynamic ARP protection is implemented in the following ways on a switch:
You can configure dynamic ARP protection only from the CLI; you cannot
configure this feature from the web or menu interfaces.
Line rate—Dynamic ARP protection copies ARP packets to the switch
CPU, evaluates the packets, and then re-forwards them through the switch
software. During this process, if ARP packets are received at too high a
line rate, some ARP packets may be dropped and will need to be retrans-
mitted.
The SNMP MIB, HP-ICF-ARP-PROTECT-MIB, is created to configure
dynamic ARP protection and to report ARP packet-forwarding status and
counters.
10-16

Table of Contents

Other manuals for HP PROCURVE 2910AL

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HP PROCURVE 2910AL and is the answer not in the manual?

HP PROCURVE 2910AL Specifications

General IconGeneral
ModelHP ProCurve 2910al
Switching Capacity128 Gbps
Throughput95.2 Mpps
ManagementWeb, CLI, SNMP
Jumbo Frame SupportYes
ManageableYes
Power100-240 VAC
Power SupplyInternal
Operating Temperature0°C to 45°C (32°F to 113°F)
StackingYes
MAC Address Table Size32000 entries
Routing ProtocolRIP, OSPF
FeaturesIPv6, VLAN, QoS, ACLs
Operating Humidity15% to 95% non-condensing
Uplink Ports4
Power over EthernetYes (PoE+ models available)

Related product manuals