SNR S2989G-24TX-POE — настройка ARP GUARD для защиты сетевых устройств [189/553]

Превью страниц Страница 189 / 553
SNR S2989G-48TX [189/553] Introduction to arp local proxy function
S2989G-24TX Operation Manual
Chapter 3 IP services Configuration
3-27
PC4 PC5 PC6
Figure 3-6 ARP GUARD schematic diagram
We utilize the filtering entries of the switch to protect the ARP entries of important
network devices from being imitated by other devices. The basic theory of doing this is
that utilizing the filtering entries of the switch to check all the ARP messages entering
through the port, if the source address of the ARP message is protected, the messages
will be directly dropped and will not be forwarded.
ARP GUARD function is usually used to protect the gateway from being attacked. If
all the accessed PCs in the network should be protected from ARP cheating, then a large
number of ARP GUARD address should be configured on the port, which will take up a big
part of FFP entries in the chip, and as a result, might affect other applications. So this will
be improper. It is recommended that adopting FREE RESOURCE related accessing
scheme. Please refer to relative documents for details.
3.9.2
ARP GUARD Configuration Task List
1. Configure the protected IP address
Command
Explanation
Port configuration mode
arp-guard ip <addr>
no arp-guard ip <addr>
Configure/delete ARP GUARD address
3.10
ARP Local Proxy
3.10.1
Introduction to ARP Local Proxy function
PC1
Switch
A B C D
PC2
PC3

Содержание

666

Узнайте, как настроить ARP GUARD для защиты важных сетевых устройств от подделки ARP сообщений. Защитите свои устройства от атак и обеспечьте безопасность сети.