Enterasys Enterasys SecureStack B2 B2G124-24 Spezifikationen Seite 514

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 600
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 513
set arpinspection validate
18-22 DHCP Snooping and Dynamic ARP Inspection
Usage
Individualinterfacesareconfiguredas trustedoruntrusted.ThetrustconfigurationforDAIis
independentofthetrustconfigurationforDHCPsnooping.Atrustedportisaportthenetwork
administratordoesnotconsidertobeasecuritythreat.Anuntrustedportisonewhichcould
potentiallybeusedtolaunch
anetworkattack.
DAIconsidersallphysicalportsandLAGsuntrustedbydefault.Packetsarrivingontrusted
interfacesbypassallDAIvalidationchecks.
Example
Thisexampleenablesportge.1.1astrustedforDAI.
B2(su)->set arpinspection trust port ge.1.1 enable
set arpinspection validate
UsethiscommandtoconfigureadditionaloptionalARPvalidationparameters.
Syntax
set arpinspection validate {[src-mac] [dst-mac] [ip]}
Parameters
Defaults
Allparametersareoptional,butatleastoneparametermustbespecified.
Mode
Switchcommand,readwrite.
Usage
ThiscommandaddsadditionalvalidationofARPpacketsby DAI,beyondthebasicvalidation
thattheARPpacket’ssenderMACaddressandsenderIPaddressmatchanentryintheDHCP
snoopingbindingsdatabase.
srcmac Specifiesthat DAIshouldverifythatthesenderMACaddressequals
thesourceMACaddressin
theEthernetheader.
dstmac SpecifiesthatDAIshouldverifythatthetargetMACaddressequalsthe
destinationMACaddressintheEthernetheader.
ThischeckonlyappliestoARPresponses,sincethetargetMACaddress
isunspecifiedinARPrequests.
ip SpecifiesthatDAIshouldchecktheIPaddressanddropARP
packets
withaninvalidaddress.Aninvalidaddressisoneofthefollowing:
0.0.0.0
255.255.255.255
All IP multicast addresses
All class E addresses (240.0.0.0/4)
Loopback addresses (in the range 127.0.0.0/8)
Seitenansicht 513
1 2 ... 509 510 511 512 513 514 515 516 517 518 519 ... 599 600

Kommentare zu diesen Handbüchern

Keine Kommentare