EasyManuals Logo

HPE FlexNetwork 5510 HI Series Security Configuration Guide

HPE FlexNetwork 5510 HI Series
551 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #430 background imageLoading...
Page #430 background image
417
Step
Command
Remarks
1. Enter system view.
system-view
N/A
2.
Enable ARP packet source MAC
address consistency check.
arp valid-check enable
By default, ARP packet source
MAC address consistency
check is disabled.
Configuring ARP active acknowledgement
Configure this feature on gateways to prevent user spoofing.
ARP active acknowledgement prevents a gateway from generating incorrect ARP entries.
In strict mode, a gateway performs more strict validity checks before creating an ARP entry:
• Upon receiving an ARP request destined for the gateway, the gateway sends an ARP reply but
does not create an ARP entry.
• Upon receiving an ARP reply, the gateway determines whether it has resolved the sender IP
address:
ï‚¡ If yes, the gateway performs active acknowledgement. When the ARP reply is verified as
valid, the gateway creates an ARP entry.
ï‚¡ If no, the gateway discards the packet.
To configure ARP active acknowledgement:
Step
Command
Remarks
1. Enter system view.
system-view
N/A
2.
Enable the ARP active
acknowledgement feature.
arp active-ack
[
strict
]
enable
By default, this feature is disabled.
Configuring authorized ARP
Authorized ARP entries are generated based on the DHCP clients' address leases on the DHCP
server or dynamic client entries on the DHCP relay agent. For more information about DHCP server
and DHCP relay agent, see Layer 3—IP Services Configuration Guide.
With authorized ARP enabled, an interface is disabled from learning dynamic ARP entries. This
feature prevents user spoofing and allows only authorized clients to access network resources.
Configuration procedure
To enable authorized ARP:
Step
Command
Remarks
1. Enter system view.
system-view
N/A
2. Enter interface view.
interface
interface-type
interface-number
The device supports the following
interface types:
• Layer 3 Ethernet interface.
• Layer 3 aggregate interface.
• VLAN interface.

Table of Contents

Other manuals for HPE FlexNetwork 5510 HI Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HPE FlexNetwork 5510 HI Series and is the answer not in the manual?

HPE FlexNetwork 5510 HI Series Specifications

General IconGeneral
BrandHPE
ModelFlexNetwork 5510 HI Series
CategorySwitch
LanguageEnglish

Related product manuals