EasyManuals Logo

HP V1910 User Manual

HP V1910
483 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #328 background imageLoading...
Page #328 background image
316
a.
Man-in-the-middle attack
Switch
Host A
Host B
IP_A
MAC_A
IP_B
MAC_B
IP_C
MAC_C
Host C
Forged
ARP reply
Forged
ARP reply
ARP detection mechanism
With ARP detection enabled for a specific VLAN, ARP messages arrived on any interface in the VLAN are
redirected to the CPU to have their MAC and IP addresses checked. ARP messages that pass the check are
forwarded, and other ARP messages are discarded.
Table 95 ARP detection based on DHCP snooping entries/802.1X security entries/static IP-to-MAC
bindings
With this feature enabled, the device compares the source IP and MAC addresses of an ARP packet
received from the VLAN against the DHCP snooping entries, 802.1X security entries, or static IP-to-MAC
binding entries. You can specify a detection type or types as needed.
After you enable ARP detection based on DHCP snooping entries for a VLAN,
Upon receiving an ARP packet from an ARP untrusted port, the device compares the ARP packet
against the DHCP snooping entries. If a match is found, that is, the parameters (such as IP address,
MAC addresses, port index, and VLAN ID) are consistent, the ARP packet passes the check; if not, the
ARP packet cannot pass the check.
Upon receiving an ARP packet from an ARP trusted port, the device does not check the ARP packet.
If ARP detection is not enabled for the VLAN, the ARP packet is not checked even if it is received from
an ARP untrusted port.
After you enable ARP detection based on 802.1X security entries, the device, upon receiving an ARP packet
from an ARP untrusted port, compares the ARP packet against the 802.1X security entries.
If an entry with identical source IP and MAC addresses, port index, and VLAN ID is found, the ARP
packet is considered valid.
If an entry with no matching IP address but with a matching OUI MAC address is found, the ARP
packet is considered valid.
Otherwise, the packet is considered invalid and discarded.

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HP V1910 and is the answer not in the manual?

HP V1910 Specifications

General IconGeneral
Switching Capacity56 Gbps
Forwarding Rate41.7 Mpps
ManageableYes
Form FactorRack-mountable
FeaturesVLAN, QoS, Link Aggregation
Operating Temperature0°C to 45°C
Operating Humidity10% to 90% (non-condensing)
Ports24 x 10/100/1000 + 4 x SFP

Related product manuals