4.2 Security Management

To access the Security Management Menu, type t in the Configuration Menu. Use the listed command letters to configure port security, duplicate IP detection and trap, and station movement trap, or to display the duplicated IP list and reset all security parameters to factory default.

IntraCore 35160-T Security Management Menu

Duplicated-IP

Monitoring Status

: Enable

Duplicated-IP

Trap Status

: Enable

Station Movement Trap Status

: Disable

<Cmd> <Description>

pPort Security Configuration

x802.1X Configuration

dToggle Duplicated-IP Detection Enable/Disable

iToggle Duplicated-IP Trap Enable/Disable

lDisplay Duplicated-IP List

sToggle Station Movement Trap Enable/Disable

rReset All Security Configuration to Factory Default

qReturn to previous menu

root>

Important! For any traps (alerts) to be sent, one or more devices must be designated as trap receivers. See “SNMP Configuration” in Chapter 3.

4.2.1 Duplicated IP Detection and Trap

The duplicated IP detection and duplicated IP trap security measures allow the user to monitor the use of a single IP address by two stations.

If duplicated IP detection is enabled, the switch starts monitoring the broadcast Address Resolution Protocol (ARP) traffic from all of its ports, to detect duplicated IP address conditions. When duplicate IP addresses are used on the system, the MAC addresses of both stations and the ports they accessed are logged.

If both duplicated IP detection and duplicated IP trap are enabled, the designated trap receiver gets an alert each time a duplicated IP address is used on the system. In order to send duplicated IP traps, duplicated IP detection must be enabled.

By default, duplicated IP detection and trapping are enabled.

Enabling and Disabling Duplicated IP Detection

To enable or disable detection of duplicated IP addresses:

1.From the Configuration Menu, type t to access the Security Management Menu.

2.Type d to toggle duplicated IP detection.

Enabling and Disabling Duplicated IP Trap

To enable the sending of a trap when a duplicated IP is detected, first enable duplicated IP detection. See the previous subsection, “Enabling and Disabling Duplicated IP Detection.”

To enable or disable the sending of a trap when a duplicated IP is detected:

1.From the Configuration Menu, type t to access the Security Management Menu.

2.Type i to toggle duplicated IP trap.

Viewing a List of Duplicated IP Addresses

To view a list of duplicated IP addresses that have been detected at the switch:

47

Page 47
Image 47
Asante Technologies 35160 user manual Duplicated IP Detection and Trap, Enabling and Disabling Duplicated IP Detection