ZXA10C300CongurationManual(CLI)
mac-move-report:enable
mac-move-reportinterval:30[minutes]
mac-anti-spoofing:enable
uplink-protect:enable
4.(Optional)QuerytheMACmovelog.
ZXAN#showsecuritymac-move-log
Flag*--macMoveisforbiddenbysystem.
thetotalmac-move-lognum:2
-------------------------------------------------------------------------
mac-addressvlancfgMacProtectmoveToPortmoveToIfIdmoveCount
indextrapFlagdetectorqueryPortmoveFromPortmoveFromIfIdtrapCount
-------------------------------------------------------------------------
0002.0304.0506100UNNEEDinner-port_1/12/1unknown(0)1
1SENDEDMPUNNEEDinner-port_1/5/1unknown(0)1
-------------------------------------------------------------------------
0002.0304.0507100UNNEEDinner-port_1/12/2unknown(0)1
2*SENDEDMPUNNEEDinner-port_1/5/1unknown(0)1
–EndofSteps–
14.3ConguringtheARPAnti-Spoong
TheARPanti-spoongpreventstheARPspoongonuserside.
Context
TheZXA10C300supportsuser-sideARPanti-spoongfunction,whichisimplemented
basedonthefollowingARPentries:
lTheARPentriesinsertedbytheDHCPmodule
lTheARPentriesofDHCPsnoopingstaticbindingitemconguredbytheIPsource
Guardmodule
ARPanti-spoongfunctionisbasedonbothVLANandserviceport.Onlywhenthe
ARPanti-spoongfunctionsonbothVLANandserviceportareenabled,thesystemcan
implementARPanti-spoongonARPpacketswiththespecicVLANtag.
WhenreceivinganARPpacket,theZXA10C300comparesthepacketwiththeknown
ARPentries.IfthesourceIPaddressofthereceivedARPpacketandtheVLANexist
intheARPtable,theZXA10C300checkswhethertheMACaddressesarethesame.If
theyaredifferent,theZXA10C300considersthepacketasanARPspoongbehaviorand
discardsit.
TheARPanti-spoongfunctioncanbeconguredwithupto256VLANs.
14-10
SJ-20130520164529-007|2013-06-30(R1.0)ZTEProprietaryandCondential