Enterasys Enterasys SecureStack B2 B2G124-24 Specifikace Strana 508

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 600
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 507
clear dhcpsnooping limit
18-16 DHCP Snooping and Dynamic ARP Inspection
clear dhcpsnooping limit
Usethiscommandtoresettheratelimitvaluestothedefaultsof15packetspersecondwitha
burstintervalof1second.
Syntax
clear dhcpsnooping limit port-string
Parameters
Defaults
None.
Mode
Switchcommand,readwrite.
Example
Thisexampleresetstheratelimitvaluestotheirdefaultsonportge.1.1.
B2
(su)->clear dhcpsnooping limit ge.1.1
Dynamic ARP Inspection Overview
DynamicARPinspection(DAI)isasecurityfeaturethatrejectsinvalidandmaliciousARP
packets.Thefeaturepreventsaclassofmaninthemiddleattackswhereanunfriendlystation
interceptstrafficforotherstationsbypoisoningtheARPcachesofitsunsuspectingneighbors.
ARPpoisoningisatacticwherean
attackerinjectsfalseARPpacketsintothesubnet,normallyby
broadcastingARPresponsesinwhichtheattackerclaimstobe someoneelse.Bypoisoningthe
ARPcache,amalicioususercaninterceptthetrafficintendedforotherhostsonthenetwork.
TheDynamicARPInspectionapplicationperformsARPpacketvalidation.
WhenDAIisenabled,
itverifiesthatthesenderMACaddressandthesourceIPaddressareavalidpairintheDHCP
snoopingbindingdatabaseanddropsARPpacketswhosesenderMACaddressandsenderIP
addressdonotmatchanentryinthedatabase.AdditionalARPpacketvalidationcan
be
configured.
IfDHCPsnoopingisdisabledontheingressVLANorthereceiveinterfaceistrustedforDHCP
snooping,ARPpacketsaredropped.
Functional Description
DAIisenabledonVLANs,effectivelyenablingDAIontheinterfaces(physicalportsorLAGs)that
aremembersofthatVLAN.Individualinterfacesareconfiguredastrustedoruntrusted.Thetrust
configurationforDAIisindependentofthetrustconfigurationforDHCPsnooping.Atrusted
portisaportthenetwork
administratordoesnotconsidertobeasecuritythreat.Anuntrusted
portisonewhichcouldpotentiallybeusedtolaunchanetworkat tack.
DAIconsidersallphysicalportsandLAGsuntrustedbydefault.
portstring Specifiestheportorportstowhichthiscommandapplies.
Zobrazit stránku 507
1 2 ... 503 504 505 506 507 508 509 510 511 512 513 ... 599 600

Komentáře k této Příručce

Žádné komentáře