Configuring ARP Gateway Anti-Collision
Context
If an attacker forges the gateway address to send ARP packets with the source IP address being the IP address of the gateway on the LAN, ARP entries on hosts in the LAN record the incorrect gateway address. As a result, all traffic from user hosts to the gateway is sent to the attacker and the attacker intercepts user information. Communication of users is interrupted. To defend against bogus gateways, you can enable the ARP bogus gateway attack defense function on gateways directly connected to the host.
- The interface receiving the packet is a VLANIF or VBDIF interface.
- The source IP address in the ARP packet is the same as the IP address of the interface that receives the packet.
- The source MAC address in the Ethernet packet header and source MAC address in the ARP packet are different from the interface MAC address.
- The source MAC address in the received packet is not a VRRP virtual MAC address.
If the check-all parameter is specified and the source IP address in a received ARP packet is the same as the local address, the switch considers that the ARP packet conflicts with the gateway address.
The check-all parameter enhances the ARP gateway anti-collision function. When the switch detects a bogus gateway, the gateway reports an alarm and sends a gratuitous ARP packet so that user hosts can update the ARP entries.
Procedure
- Run system-view
The system view is displayed.
- Run arp anti-attack gateway-duplicate [ check-all ] enable
ARP gateway anti-collision is enabled.
By default, ARP gateway anti-collision is disabled.
CE12800E does not support the check-all parameter after having the ED-E, EG-E, and EGA-E series cards installed.
Follow-up Procedure
- To view the ARP gateway anti-collision entries in the case that the check-all parameter is not specified for the ARP gateway anti-collision function, run the display arp anti-attack gateway-duplicate item command.
- To view the ARP gateway anti-collision entries in the case that the check-all parameter is specified for the ARP gateway anti-collision function, run the display arp anti-attack gateway-duplicate information command.
CE12800E does not support the command after having the ED-E, EG-E, and EGA-E series cards installed.