HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 193

Configuration procedure, Configuration example, Network requirements

Page 193 highlights

• Do not configure both the arp filter source and arp filter binding commands on an interface. • If ARP filtering works with ARP detection and ARP snooping, ARP filtering applies first. Configuration procedure To configure ARP filtering: Step 1. Enter system view. 2. Enter Ethernet interface or aggregate interface view. 3. Enable ARP filtering and configure a permitted entry. Command system-view Remarks N/A interface interface-type interface-number N/A arp filter binding ip-address mac-address By default, ARP filtering is disabled. Configuration example Network requirements As shown in Figure 65, the IP and MAC addresses of Host A are 10.1.1.2 and 000f-e349-1233 respectively. The IP and MAC addresses of Host B are 10.1.1.3 and 000f-e349-1234. Configure ARP filtering on Ten-GigabitEthernet 1/1/5 and Ten-GigabitEthernet 1/1/6 of Switch B to permit ARP packets from the two hosts only. Figure 65 Network diagram Configuration procedure # Configure ARP filtering on Switch B. system-view [SwitchB] interface ten-gigabitethernet 1/1/5 [SwitchB-Ten-GigabitEthernet1/1/5] arp filter binding 10.1.1.2 000f-e349-1233 [SwitchB-Ten-GigabitEthernet1/1/5] quit [SwitchB] interface ten-gigabitethernet 1/1/6 184

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

184
Do not configure both the
arp filter source
and
arp filter binding
commands on an interface.
If ARP filtering works with ARP detection and ARP snooping, ARP filtering applies first.
Configuration procedure
To configure ARP filtering:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Ethernet interface or
aggregate interface view.
interface
interface-type interface-number
N/A
3.
Enable ARP filtering and
configure a permitted entry.
arp filter binding
ip-address
mac-address
By default, ARP filtering is
disabled.
Configuration example
Network requirements
As shown in
Figure 65
, the IP and MAC addresses of Host A are 10.1.1.2 and 000f-e349-1233
respectively. The IP and MAC addresses of Host B are 10.1.1.3 and 000f-e349-1234.
Configure ARP filtering on Ten-GigabitEthernet 1/1/5 and Ten-GigabitEthernet 1/1/6 of Switch B to
permit ARP packets from the two hosts only.
Figure 65
Network diagram
Configuration procedure
# Configure ARP filtering on Switch B.
<SwitchB> system-view
[SwitchB] interface ten-gigabitethernet 1/1/5
[SwitchB-Ten-GigabitEthernet1/1/5] arp filter binding 10.1.1.2 000f-e349-1233
[SwitchB-Ten-GigabitEthernet1/1/5] quit
[SwitchB] interface ten-gigabitethernet 1/1/6