HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 253

Configuring ARP restricted forwarding, Displaying and maintaining ARP detection, Command, Remarks

Page 253 highlights

Step 1. Enter system view. Command system-view Remarks N/A 2. Enter VLAN view. 3. Enable ARP detection for the VLAN. vlan vlan-id arp detection enable N/A Disabled by default. 4. Return to system view. quit N/A 5. Enable ARP packet validity check and specify the objects to be checked. arp detection validate { dst-mac | ip | src-mac } * Disabled by default. 6. Enter Layer 2 Ethernet port/Layer 2 aggregate interface view. interface interface-type interface-number N/A 7. Configure the port as a trusted port on which ARP detection does not apply. arp detection trust Optional. The port is an untrusted port by default. Configuring ARP restricted forwarding ARP restricted forwarding controls the forwarding of ARP packets that are received on untrusted ports and have passed ARP detection in the following cases: • If the packets are ARP requests, they are forwarded through the trusted ports. • If the packets are ARP responses, they are forwarded according to their destination MAC address. If no match is found in the MAC address table, they are forwarded through the trusted ports. Before performing the following configuration, make sure you have configured the arp detection enable command. To enable ARP restricted forwarding: Step 1. Enter system view. 2. Enter VLAN view. 3. Enable ARP restricted forwarding. Command system-view vlan vlan-id arp restricted-forwarding enable Remarks N/A N/A Disabled by default Displaying and maintaining ARP detection Task Display the VLANs enabled with ARP detection. Display the ARP detection statistics. Clear the ARP detection statistics. Command display arp detection [ | { begin | exclude | include } regular-expression ] display arp detection statistics [ interface interface-type interface-number ] [ | { begin | exclude | include } regular-expression ] reset arp detection statistics [ interface interface-type interface-number ] Remarks Available in any view Available in any view Available in user view 243

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

243
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter VLAN view.
vlan
vlan-id
N/A
3.
Enable ARP detection for the
VLAN.
arp detection enable
Disabled by default.
4.
Return to system view.
quit
N/A
5.
Enable ARP packet validity
check and specify the objects to
be checked.
arp detection validate
{
dst-mac
|
ip
|
src-mac
} *
Disabled by default.
6.
Enter Layer 2 Ethernet
port/Layer 2 aggregate
interface view.
interface
interface-type
interface-number
N/A
7.
Configure the port as a trusted
port on which ARP detection
does not apply.
arp detection trust
Optional.
The port is an untrusted port
by default.
Configuring ARP restricted forwarding
ARP restricted forwarding controls the forwarding of ARP packets that are received on untrusted ports
and have passed ARP detection in the following cases:
If the packets are ARP requests, they are forwarded through the trusted ports.
If the packets are ARP responses, they are forwarded according to their destination MAC address.
If no match is found in the MAC address table, they are forwarded through the trusted ports.
Before performing the following configuration, make sure you have configured the
arp detection enable
command.
To enable ARP restricted forwarding:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter VLAN view.
vlan
vlan-id
N/A
3.
Enable ARP restricted forwarding.
arp restricted-forwarding enable
Disabled by default
Displaying and maintaining ARP detection
Task
Command
Remarks
Display the VLANs enabled
with ARP detection.
display arp detection
[
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display the ARP detection
statistics.
display arp detection statistics
[
interface
interface-type interface-number
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Clear the ARP detection
statistics.
reset arp detection statistics
[
interface
interface-type interface-number
]
Available in user view