Qtech QSW-2900-24T-AC [120/209] Enable disable arp anti spoofing

7-118
decompiling):
arp anti-flood bind blackhole { mac | all }
For example
! Bind mac00:0a:5a:00:02:02
QTECH(config)#arp anti-flood bind blackhole 00:0a:5a:00:02:02
! Bind all blackhole mac generated by all arp anti-flood
QTECH(config)#arp anti-flood bind blackhole all
7.2.8 Enable/disable ARP anti-spoofing
ARP anti-spoofing is used to check the match of ARP packet and configured static ARP. After enabling this function,
all ARP through switch will be redirected to CPU. If source IP, source MAC, interface number, vlan id and static
ARP are totally matched, it is thought to be valid and permitted normal handling and transmit. If not, drop it. If there
is not corresponded static ARP table item, handle it as strategy of configuring unknown arp packet: drop it or flood
(send to each interface) and ARP anti-flood is defaulted to be disabled. Use this command in global configuration
mode to enable it:
Enable arp anti-spoofing
QTECH(config)#arp anti-spoofing
Disable arp anti-spoofing
QTECH(config)#no arp anti-spoofing
7.2.9 Configure unknown ARP packet handling strategy
Use following command to configure unknown ARP packet handling strategy.
arp anti-spoofing unknown { discard | flood }
Example
! Configure unknown ARP packet handling strategy to be flood
QTECH(config)#arp anti-spoofing unknow flood
Strategy discard means to drop unknown arp packet without corresponded static arp. Strategy flood

Содержание

Скачать
Случайные обсуждения