<HUAWEI> arp -a Interface: 10.10.10.150 --- 0xb Internet address Physical address Type 10.10.10.1 00-00-00-00-11-11 Dynamic 10.10.10.23 00-00-00-00-22-22 Dynamic 10.10.10.255 ff-ff-ff-ff-ff-ff Dynamic
If the gateway ARP entry on the PC does not match the IP or MAC address of the gateway, a device on the internal network may have a conflicting IP address with the gateway or the switch undergoes an ARP bogus gateway attack. Perform the following operations:
If the IP addresses conflicts, change the IP address of the device. If no IP address conflict occurs, obtain packet information on the PC to analyze the source IP addresses of ARP packets. Find out the attacker, scan virus or uninstall the attack tool on the attacker. Alternatively, configure attack defense on the gateway.
<HUAWEI> system-view [HUAWEI] arp anti-attack gateway-duplicate enable //Enable ARP gateway anti-collision. [HUAWEI] arp gratuitous-arp send enable //Enable the sending of gratuitous ARP packets.
When receiving an ARP packet, the switch considers that the packet conflicts with the gateway address in either of the following situations:
If the gateway ARP entry in a user's ARP entry does not match the IP or MAC address of the gateway, obtain packet information, find out the attack source, and eliminate the attack source or configure dynamic ARP inspection on the gateway.
<HUAWEI> system-view [HUAWEI] user-bind static ip-address 10.0.0.1 mac-address 0001-0001-0001 //Create a binding entry. [HUAWEI] user-bind static ip-address 10.0.0.11 mac-address 0002-0002-0002 [HUAWEI] interface gigabitethernet 0/0/1 //Enable dynamic ARP inspection on the interface connected to PC. [HUAWEI-GigabitEthernet0/0/1] arp anti-attack check user-bind enable [HUAWEI-GigabitEthernet0/0/1] quit
<HUAWEI> system-view [HUAWEI] dhcp enable //Enable DHCP globally. [HUAWEI] dhcp snooping enable //Enable DHCP Snooping globally. [HUAWEI] vlan 10 //Enter the VLAN where dynamic ARP inspection needs to be enabled. [HUAWEI-vlan10] dhcp snooping enable //Enable DHCP snooping in the VLAN. [HUAWEI-vlan10] dhcp snooping trusted interface gigabitethernet 0/0/3 //Configure the interface connected to DHCP server to as a trusted interface. If the switch functions as a DHCP server, this command is not required. [HUAWEI-vlan10] arp anti-attack check user-bind enable //Enable dynamic ARP inspection in the VLAN. [HUAWEI-vlan10] quit
After DHCP snooping is enabled, an entry is generated only after the PC obtains an IP address again. When the binding entry is not generated, all ARP entries from the PC are discarded. (To allow the PC to obtain an IP address quickly, disable and enable the network adapter on the PC.)