HP 6125XLG R2306-HP 6125XLG Blade Switch Layer 3 - IP Services Configuration G - Page 24

Configuring ARP snooping, Configuration procedure, Displaying and maintaining ARP snooping

Page 24 highlights

Configuring ARP snooping ARP snooping is used in Layer 2 switching networks. It creates ARP snooping entries by using information in ARP packets. If you enable ARP snooping on a VLAN, ARP packets received by any interface in the VLAN are redirected to the CPU. The CPU uses the sender IP and MAC addresses of the ARP packets, and receiving VLAN and port to create ARP snooping entries. The aging time and valid period of an ARP snooping entry are 25 minutes and 15 minutes. If an ARP snooping entry is not updated in 15 minutes, it becomes invalid and cannot be used. After that, if an ARP packet matching the entry is received, the entry becomes valid, and its aging timer restarts. If the aging timer of an ARP entry expires, the entry is removed. If the ARP snooping device receives an ARP packet that has the same sender IP address as a valid ARP snooping entry, but with a different sender MAC address, it assumes it has been attacked. The ARP snooping entry becomes invalid, and is removed after 25 minutes. Configuration procedure To enable ARP snooping for a VLAN: Step 1. Enter system view. 2. Enter VLAN view. 3. Enable ARP snooping Command system-view vlan vlan-id arp snooping enable Remarks N/A N/A By default, ARP snooping is disabled. Displaying and maintaining ARP snooping Execute display commands in any view and reset commands in user view. Task Display ARP snooping entries. Remove ARP snooping entries. Command display arp snooping [ vlan vlan-id ] [ slot slot-number ] [ count ] display arp snooping ip ip-address [ slot slot-number ] reset arp snooping [ ip ip-address | vlan vlan-id ] 15

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230

15
Configuring ARP snooping
ARP snooping is used in Layer 2 switching networks. It creates ARP snooping entries by using information
in ARP packets.
If you enable ARP snooping on a VLAN, ARP packets received by any interface in the VLAN are
redirected to the CPU. The CPU uses the sender IP and MAC addresses of the ARP packets, and receiving
VLAN and port to create ARP snooping entries.
The aging time and valid period of an ARP snooping entry are 25 minutes and 15 minutes. If an ARP
snooping entry is not updated in 15 minutes, it becomes invalid and cannot be used. After that, if an ARP
packet matching the entry is received, the entry becomes valid, and its aging timer restarts. If the aging
timer of an ARP entry expires, the entry is removed.
If the ARP snooping device receives an ARP packet that has the same sender IP address as a valid ARP
snooping entry, but with a different sender MAC address, it assumes it has been attacked. The ARP
snooping entry becomes invalid, and is removed after 25 minutes.
Configuration procedure
To enable ARP snooping for a VLAN:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter VLAN view.
vlan
vlan-id
N/A
3.
Enable ARP snooping
arp snooping enable
By default, ARP snooping is disabled.
Displaying and maintaining ARP snooping
Execute
display
commands in any view and
reset
commands in user view.
Task
Command
Display ARP snooping entries.
display arp snooping
[
vlan
vlan-id
] [
slot
slot-number
] [
count
]
display arp snooping ip
ip-address
[
slot
slot-number
]
Remove ARP snooping entries.
reset arp snooping
[
ip
ip-address
|
vlan
vlan-id
]