SNR S2989G-24TX-UPS [184/553] Arp scanning prevention troubleshooting help

Превью страниц Страница 184 / 553
SNR S2989G-24TX [184/553] Arp scanning prevention troubleshooting help
S2989G-24TX Operation Manual
Chapter 3 IP services Configuration
3-22
SWITCH B
E1/0/1
E1/0/19
SWITCH A
E1/0/2
Server
PC PC
192.168.1.100/24
Figure 3-5 ARP scanning prevention typical configuration example
In the network topology above, port E1/0/1 of SWITCH B is connected to port E1/0/19
of SWITCH A, the port E1/0/2 of SWITCH A is connected to file server (IP address is
192.168.1.100/24), and all the other ports of SWITCH A are connected to common PC.
The following configuration can prevent ARP scanning effectively without affecting the
normal operation of the system.
SWITCH A configuration task sequence:
SwitchA(config)#anti-arpscan enable
SwitchA(config)#anti-arpscan recovery time 3600
SwitchA(config)#anti-arpscan trust ip 192.168.1.100 255.255.255.0
SwitchA(config)#interface ethernet1/0/2
SwitchA (Config-If-Ethernet1/0/2)#anti-arpscan trust port
SwitchA (Config-If-Ethernet1/0/2)#exit
SwitchA(config)#interface ethernet1/0/19
SwitchA (Config-If-Ethernet1/0/19)#anti-arpscan trust supertrust-port
Switch A(Config-If-Ethernet1/0/19)#exit
SWITCHB configuration task sequence:
Switch B(config)# anti-arpscan enable
SwitchB(config)#interface ethernet1/0/1
SwitchB(Config-If-Ethernet1/0/1)#anti-arpscan trust port
SwitchB(Config-If-Ethernet1/0/1)exit
3.7.4
ARP Scanning Prevention Troubleshooting Help
ARP scanning prevention is disabled by default. After enabling ARP scanning

Содержание

666