SNR S2989G-48TX-RPS — настройка ARP и динамической проверки ARP для сетевых устройств [194/553]

Превью страниц Страница 194 / 553
SNR S2989G-48TX-RPS [194/553] Gratuitous arp troubleshooting
S2989G-24TX Operation Manual
Chapter 3 IP services Configuration
3-32
Switch(config)#exit
2. Configure gratuitous ARP specifically for only one interface at one time.
Switch(config)#interface vlan 10
Switch(Config-if-Vlan10)#ip gratuitous-arp 300
Switch(Config-if-Vlan10)#exit
Switch(config) #exit
3.11.4
Gratuitous ARP Troubleshooting
Gratuitous ARP is disabled by default. And when gratuitous ARP is enabled, the
debugging information about ARP packets can be retrieved through the command debug
ARP send.
If gratuitous ARP is enabled in global configuration mode, it can be disabled only in
global configuration mode. If gratuitous ARP is configured in interface configuration mode,
the configuration can only be disabled in interface configuration mode.
3.12
Dynamic ARP Inspection
3.12.1
Introduction to Dynamic ARP Inspection
Configuration
DAI (Dynamic ARP Inspection) is a kind of security property that it can verificate the
ARP data packets in the network. Through DAI, the administrator can intercept, record
and drop the ARP data packets which have the invalid MAC address/IP address.
The dynamic ARP inspection judges the legality of the ARP data packets according to
the lawful IP and MAC addresses in a trusted database. This database can be created by
the manual static appointing or the dynamic DHCP monitoring learning. If the ARP data
packet is received from the trusted port, the switch will not inspect it and forward it directly.
If the ARP data packet is received from the untrusted port, the switch will only forward the
lawful data packet. For the illegal data, it will drop the data directly and record this action.
Notice: The trusted/untrusted port above is not the one of DHCP monitoring, it is the
rules that the dynamic ARP inspection function needs to configure.
3.12.2
Dynamic ARP Inspection Configuration Task
List

Содержание

666

Узнайте, как настроить gratuitous ARP и динамическую проверку ARP для повышения безопасности сети. Подробные инструкции и советы по устранению неполадок.