944
Predefined user roles
network-admin
Parameters
strict
: Enables strict mode for ARP active acknowledgement.
Usage guidelines
Configure this feature on gateways to prevent user spoofing.
In strict mode, a gateway learns an entry only when ARP active acknowledgement is successful
based on the correct ARP resolution.
Examples
# Enable the ARP active acknowledgement feature.
<Sysname> system-view
[Sysname] arp active-ack enable
Authorized ARP commands
arp authorized enable
Use
arp authorized enable
to enable authorized ARP on an interface.
Use
undo arp authorized enable
to disable authorized ARP on an interface.
Syntax
arp authorized enable
undo arp authorized enable
Default
Authorized ARP is disabled on the interface.
Views
Layer 3 Ethernet interface/subinterface view
Layer 3 aggregate interface/subinterface view
VLAN interface view
Predefined user roles
network-admin
Examples
# Enable authorized ARP on GigabitEthernet 1/0/1.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] arp authorized enable
ARP attack detection commands
This feature is supported only on the following ports:
•
Layer 2 Ethernet ports on the following modules:
HMIM-8GSW.
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...