S1720, S2700, S5700, and S6720 V200R011C10 Configuration Guide - Security

This document describes the configurations of Security, including ACL, local attack defense, MFF, attack defense, traffic suppression and storm control, ARP security, Port security, DHCP snooping, ND snooping, PPPoE+, IPSG, SAVI, URPF, keychain, MPAC, separating the management plane from the service plane, security risks, PKI.

Configuring Defense Against ARP Spoofing Attacks

Configuring Defense Against ARP Spoofing Attacks

If an attacker sends bogus ARP packets to a network device or user host, the device or host modifies the local ARP entries, leading to packet forwarding failures. The function of defense against ARP spoofing attacks can prevent such attacks.

Pre-configuration Tasks

Before configuring defense against ARP spoofing attacks, connect interfaces and set physical parameters for the interfaces to ensure that the physical status of the interfaces is Up.

Configuration Procedure

Operations in the configuration procedure can be performed in any sequence.