SNR S2989G-24TX-UPS — настройка ARP безопасности для защиты сети от атак [188/553]

Превью страниц Страница 188 / 553
SNR S2989G-24TX [188/553] Introduction to arp guard
S2989G-24TX Operation Manual
Chapter 3 IP services Configuration
3-26
Switch(Config-If-Vlan2)#arp 192.168.1.2 00-00-00-00-00-02 interface eth 1/0/2
Switch(Config-If-Vlan2#interface vlan 3
Switch(Config-If-Vlan3)#arp 192.168.2.3 00-00-00-00-00-03 interface eth 1/0/2
Switch(Config-If-Vlan3)#exit
Switch(Config)#ip arp-security learnprotect
Switch(Config)#
Switch(config)#ip arp-security convert
If the environment changing, it enable to forbid ARP refresh, once it learns ARP
property, it wont be refreshed by new ARP reply packet, and protect use data from
sniffing.
Switch#config
Switch(config)#ip arp-security updateprotect
3.9
ARP GUARD
3.9.1
Introduction to ARP GUARD
There is serious security vulnerability in the design of ARP protocol, which is any
network device, can send ARP messages to advertise the mapping relationship between
IP address and MAC address. This provides a chance for ARP cheating. Attackers can
send ARP REQUEST messages or ARP REPLY messages to advertise a wrong mapping
relationship between IP address and MAC address, causing problems in network
communication. The danger of ARP cheating has two forms: 1. PC4 sends an ARP
message to advertise that the IP address of PC2 is mapped to the MAC address of PC4,
which will cause all the IP messages to PC2 will be sent to PC4, thus PC4 will be able to
monitor and capture the messages to PC2; 2. PC4 sends ARP messages to advertise that
the IP address of PC2 is mapped to an illegal MAC address, which will prevent PC2 from
receiving the messages to it. Particularly, if the attacker pretends to be the gateway and
do ARP cheating, the whole network will be collapsed.

Содержание

666

Изучите, как настроить ARP безопасность для защиты вашей сети от атак. Узнайте о методах предотвращения ARP мошенничества и обеспечении безопасности данных.