Tp-Link T1700G-28TQ V2 — настройка безопасности сети: ARP Inspection и ARP Defend [596/772]

Превью страниц Страница 596 / 772
Tp-Link T1700G-28TQ V2 [596/772] With arp defend enabled the switch can terminate receiving the arp packets for 300 seconds when the transmission speed of the legal arp packet on the port exceeds the defined value so as to avoid arp attack flood
Configuring Network Security ARP Inspection Configurations
Configuration Guide
571
Switch(config)#interface gigabitEthernet 1/0/1
Switch(config-if)#ip arp inspection trust
Switch(config-if)#show ip arp inspection
ARP detection global status: Enabled
Port Trusted
Gi1/0/1 YES
Gi1/0/2 NO
......
Switch(config-if)#end
Switch#copy running-config startup-config
4.2.2 Configuring ARP Defend
With ARP Defend enabled, the switch can terminate receiving the ARP packets for 300
seconds when the transmission speed of the legal ARP packet on the port exceeds the
defined value so as to avoid ARP Attack flood.
Follow these steps to configure ARP Defend:
Step 1 configure
Enter global configuration mode.
Step 2 interface {fastEthernet
port
| range fastEthernet
port-list
| gigabitEthernet
port
| range
gigabitEthernet
port-list
| ten-gigabitEthernet
port
| range ten-gigabitEthernet
port-list
]
Enter interface configuration mode.
Step 3 ip arp inspection
Enable the ARP defend feature on the port.
Step 4 ip arp inspection limit-rate
value
Specify the maximum number of the ARP packets can be received on the port per second.
value:
Specify the limit rate value. The valid values are from 10 to 100 pps (packets/second),
and the default value is 15.
Step 5 show ip arp inspection interface
(Optional) View the configurations and status of the ports.
Step 6 ip arp inspection recover
(Optional) For ports which the speed of receiving ARP packets has exceeded the limit, use
this command to restore the port from Discard status to Normal status.

Содержание

3073

Узнайте, как настроить ARP Inspection и ARP Defend для защиты сети от атак. Подробное руководство по конфигурации и управлению ARP-пакетами.