3Com WX3000 operation manual Displaying and Maintaining ARP, ARP Configuration Example

Models: WX3000

1 715
Download 715 pages 21.26 Kb
Page 423
Image 423

Displaying and Maintaining ARP

 

To do…

Use the command…

Remarks

 

Display specific ARP mapping table

display arp [ static dynamic

 

 

entries

ip-address ]

 

 

 

 

 

 

Display the ARP mapping entries

display arp [ dynamic static ]

 

 

related to a specified string in a

 

 

{ begin include exclude } text

 

 

specified way

 

 

 

 

 

 

 

 

 

Display the number of the ARP

display arp count [ [ dynamic

Available in any view

 

static ] [ { begin include

 

entries of a specified type

 

exclude } text ] ip-address ]

 

 

 

 

 

 

 

 

 

Display the statistics about the

display arp detection statistics

 

 

untrusted ARP packets dropped by

interface interface-type

 

 

the specified port

interface-number

 

 

 

 

 

 

Display the setting of the ARP aging

display arp timer aging

 

 

timer

 

 

 

 

reset arp [ dynamic static

 

 

Clear specific ARP entries

interface interface-type

Available in user view

 

 

interface-number ]

 

 

 

 

 

ARP Configuration Example

ARP Basic Configuration Example

Network requirement

z

z

z

Disable ARP entry check on the device.

Set the aging time for dynamic ARP entries to 10 minutes.

Add a static ARP entry, with the IP address being 192.168.1.1, the MAC address being 000f-e201-0000, and the outbound port being GigabitEthernet 1/0/10 of VLAN 1.

Configuration procedure

<device> system-view

[device] undo arp check enable

[device] arp timer aging 10

[device] arp static 192.168.1.1 000f-e201-0000 1 gigabitethernet 1/0/10

ARP Attack Detection Configuration Example

Network requirements

As shown in Figure 1-4, GigabitEthernet 1/0/1 of Switch A connects to DHCP Server; GigabitEthernet 1/0/2 connects to Client A, GigabitEthernet 1/0/3 connects to Client B. GigabitEthernet 1/0/1, GigabitEthernet 1/0/2 and GigabitEthernet 1/0/3 belong to VLAN 1.

z

z

Enable DHCP snooping on Switch A and specify GigabitEthernet 1/0/1 as the DHCP snooping trusted port.

Enable ARP attack detection in VLAN 1 to prevent ARP man-in-the-middle attacks, and specify GigabitEthernet 1/0/1 as the ARP trusted port.

1-8

Page 423
Image 423
3Com WX3000 operation manual Displaying and Maintaining ARP, ARP Configuration Example, ARP Basic Configuration Example