D-Link DWS-4026 Product Manual - Page 208
Configuring Dynamic ARP Inspection, DAI Configuration, DAI C
UPC - 790069325533
View all D-Link DWS-4026 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 208 highlights
D-Link Unified Access System Software User Manual 12/10/09 Field GARP Leave All Timer (centisecs) Table 112: GARP Port Configuration Fields (Cont.) Description Displays time lapse, in centiseconds, that all switches wait before leaving the GARP state. The leave all time must be greater than the leave time. The possible field value is 200-6000. The default value is 1000 centisecs. The Leave All Time controls how frequently LeaveAll PDUs are generated. A LeaveAll PDU indicates that all registrations will shortly be deregistered. Participants will need to rejoin in order to maintain registration. The Leave All Period Timer is set to a random value in the range of LeaveAllTime to 1.5*LeaveAllTime. The timer is specified in centiseconds. Enter a number between 200 and 6000 (2 to 60 seconds). The factory default is 1000 centiseconds (10 seconds). An instance of this timer exists for each GARP participant for each port. • If you make any changes to the page, click Submit to apply the changes to the system. CONFIGURING DYNAMIC ARP INSPECTION Dynamic ARP Inspection (DAI) is a security feature that rejects invalid and malicious ARP packets. DAI prevents a class of man-in-the-middle attacks, where an unfriendly station intercepts traffic for other stations by poisoning the ARP caches of its unsuspecting neighbors. The miscreant sends ARP requests or responses mapping another station's IP address to its own MAC address. DAI relies on DHCP snooping. DHCP snooping listens to DHCP message exchanges and builds a binding database of valid {MAC address, IP address, VLAN, and interface} tuples. When DAI is enabled, the switch drops ARP packets whose sender MAC address and sender IP address do not match an entry in the DHCP snooping bindings database. You can optionally configure additional ARP packet validation. DAI CONFIGURATION Use the DAI Configuration page to configure global DAI settings. To display the DAI Configuration page, click LAN > L2 Features > Dynamic ARP Inspection > DAI Configuration in the navigation tree. Figure 130: Dynamic ARP Inspection Configuration Page 208 Configuring Dynamic ARP Inspection Document 34CSFP6XXUWS-SWUM100-D7