D-Link DWS-4026 [270/741] Configuring dynamic arp inspection

D-Link DWS-4026 [270/741] Configuring dynamic arp inspection
ConfiguringDynamicARPInspection
D-Link UnifiedWiredandWirelessAccessSystem
November2011 Page270
DLinkUWSUserManual
ConfiguringDynamicARPInspection
DynamicARPInspection(DAI)isasecurityfeaturethatrejectsinvalidandmaliciousARPpackets.DAIprevents
aclassofmaninthemiddleattacks,whereanunfriendly stationinterceptstrafficforotherstationsby
poisoningtheARPcachesofitsunsuspectingneighbors.ThemiscreantsendsARPrequestsorresponses
mappinganotherstat
ionsIPaddresstoitsownMACaddress.
DAIreliesonDHCPsnooping.DHCPsnoopinglistenstoDHCPmessageexchangesandbuildsabindingdatabase
ofvalid{MACaddress,IPaddress,VLAN,andinterface}tuples.
WhenDAIisenabled,theswitchdropsARPpacket swhosesenderMACaddressandsenderIPa
ddressdonot
matchanentryintheDHCPsnoopingbindings database.YoucanoptionallyconfigureadditionalARPpacket
validation.
DAIConfiguration
UsetheDAIConfigurationpagetoconfigureglobalDAIsettings.
TodisplaytheDAIConfigurationpage,clickLAN>L2Features > DynamicARPInspection>DAIConfiguration
inthenavigationtree.
Figure172:DynamicARPInspectionConfiguration
•ClickSubmittoapplythenewconfigurationandcausethechangetotakeeffect.Thesecha
ngeswillnot
beretainedacrossapowercycleunlessaSaveconfigurationisperformed.
Table153:DynamicARPInspectionConfiguration
Field Description
ValidateSource
MAC
SelecttheDAISourceMACValidationModefortheswitch.IfyouselectEnable,Sender
MACvalidationfortheARPpacketswillbeenabled.ThedefaultisDisable.
Validate
DestinationMAC
SelecttheDAIDestinationMACValidationModefortheswitch.IfyouselectEnable,
DestinationMACvalidationfo
rtheARPResponsepacketswillbeenabled.Thedefaultis
Disable.
ValidateIP SelecttheDAIIPValidationModefortheswitch.IfyouselectEnable,IPAddressvalidation
fortheARPpacketswillbeenabled.ThedefaultisDisable.

Содержание

Похожие устройства

Скачать