72
Enhancements
Release L.11.08 Enhancements
Monitoring Dynamic ARP Protection
When dynamic ARP protection is enabled, you can monitor and troubleshoot the validation of ARP
packets with the
debug arp protect
command. Use this command when you want to debug the
following conditions:
■
The switch is dropping valid ARP packets that should be allowed.
■
The switch is allowing invalid ARP packets that should be dropped.
Figure 5. Example of debug arp protect Command
Release L.11.08 Enhancements
Release L.11.08 includes the following enhancement:
■
Enhancement (PR_1000372989) —
This enhancement enables the setting of operator/
manager username/password via SNMP. For security considerations related to this feature.
See
“Using SNMP To View and Configure Switch Authentication Features” on page 51
.
■
Enhancement —
Support has been added for the ProCurve Switch 4200vl Series single port,
10-GbE module (J8766A). See
“Operating Rules for 4200vl Series 10-GbE Port Trunks” on
■
Enhancement (PR_1000415155) —
The ARP age timer was enhanced from the previous
limit of 240 minutes to allow for configuration of values up to 1440 minutes (24 hours) or
“infinite” (99,999,999 seconds or 3.2 years). See
“ARP Age Timer Increase” on page 74
.
■
Enhancement (PR_1000408960) —
RADIUS-assigned GVRP VLANs are now supported.
See
“How RADIUS-Based Authentication Affects VLAN Operation” on page 79
.
ProCurve(config)# debug arp protect
1. ARP request is valid
"DARPP: Allow ARP request 000000-000001,10.0.0.1 for 10.0.0.2 port A1,
vlan "
2. ARP request detected with an invalid binding
"DARPP: Deny ARP request 000000-000003,10.0.0.1 port A1, vlan 1"
3. ARP response with a valid binding
"DARPP: Allow ARP reply 000000-000002,10.0.0.2 port A2, vlan 1"
4.ARP response detected with an invalid binding
"DARPP: Deny ARP reply 000000-000003,10.0.0.2 port A2, vlan 1"