EasyManuals Logo

Ruijie RG-S2900G-E Series User Manual

Ruijie RG-S2900G-E Series
943 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #651 background imageLoading...
Page #651 background image
Configuration Guide Dynamic ARP Inspection Configuration
Dynamic ARP Inspection
Configuration
Overview
DAI, an acronym of Dynamic ARP Inspection, refers to inspect the validity of
received ARP packets. Illegal ARP packets will be discarded.
ARP Spoofing Attack
ARP itself does not check the validity of incoming ARP packets, a drawback of
ARP. In this way, attackers can launch ARP spoofing attacks easily by exploiting
the drawback of the protocol. The most typical one is the man in the middle
attack, which is described as follows:
As shown in the diagram, devices A, B and C are connected to Ruijie device
and located in the same subnet. Their IP and MAC addresses are respectively
represented by (IPA, MACA), (IPB, MACB) and (IPC, MACC). When device A
needs to communicate with device B in the network layer, device A broadcasts
an ARP request in the subnet to query the MAC value of device B. Upon
receiving this ARP request packet, device B updates its ARP buffer using IPA
and MACA, and sends an ARP response. Upon receiving this response, device
A updates its ARP buffer using IPB and MACB.

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Ruijie RG-S2900G-E Series and is the answer not in the manual?

Ruijie RG-S2900G-E Series Specifications

General IconGeneral
BrandRuijie
ModelRG-S2900G-E Series
CategorySwitch
LanguageEnglish

Related product manuals