EasyManua.ls Logo

Ruijie RG-S2900G-E Series - Page 633

Ruijie RG-S2900G-E Series
943 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Configuration Guide Port-based Flow Control Configuration
information(IP or IP+MAC), and the ARP packets that not match with the legal user information. The
ARP Check function supported security function modules include:
1. Check the IP field only: IP mode for the port security and the ip source guard.
2. Check the IP+MAC field: IP+MAC binding mode for the port security, global IP+MAC binding,
802.1x IP authorization, IP Source Guard, GSN binding function.
There are two modes of ARP-CHECK: enabled, disabled mode. The disabled mode is by default.
In the enabled mode, ARP Check function is enabled or disabled according to the current
security function running state on the switch.
Enabling/disabling the following functions may trigger to enable/disable the ARP Check function:
1. Global IP+MAC binding
2. 802.1X IP authorizaiton
3. IP Source Guard
4. GSN binding
Adding the legal user for the first time or removing the last legal user may trigger to enable/disable the
ARP Check function:
1. IP+MAC binding mode for the port security
2. IP-only mode for the port security
ARP check is enabled no matter whether there is security configuration. If there is no legal user on
the port, all the arp packets from this port will be discarded.
In the disabled mode, ARP packet on the port is not checked.
Caution
Enabling ARP check of port security addresses will decrease the
maximum number of the security addresses of binding IP on all the
ports by half.
Configuring ARP-CHECK
Use the following commands to configure ARP-CHECK in the privileged mode:
Command
Actio
n
Ruijie# configure t
Enter the global configuration mode.
Ruijie(config)#interface interface-id
Enter the interface configuration mode.

Table of Contents

Related product manuals