2 prevent arp, nd spoofing configuration, Revent, Poofing configuration – PLANET XGS3-24040 User Manual

Page 197

Advertising
background image

Chapter 23 Prevent ARP, ND Spoofing Configuration

23-2

ND is neighbor discovering protocol in IPv6 protocol, and it’s similar to ARP on operation principle, therefore

we do in the same way as preventing ARP spoofing to prevent ND spoofing and attack.

23.2 Prevent ARP, ND Spoofing configuration

The steps of preventing ARP, ND spoofing configuration as below:

1.

Disable ARP, ND automatic update function

2.

Disable ARP, ND automatic learning function

3.

Changing dynamic ARP, ND to static ARP, ND

1. Disable ARP, ND automatic update function

Command

Explanation

Global Mode and Port Mode

ip arp-security updateprotect

no ip arp-security updateprotect

ipv6 nd-security updateprotect

no ipv6 nd-security updateprotect

Disable and enable ARP, ND automatic update

function.

2. Disable ARP, ND automatic learning function

Command

Explanation

Global mode and Interface Mode

ip arp-security learnprotect

no ip arp-security learnprotect

ipv6 nd-security learnprotect

no ipv6 nd-security learnprotect

Disable and enable ARP, ND automatic learning

function.

3. Function on changing dynamic ARP, ND to static ARP, ND

Command

Explanation

Global Mode and Port Mode

ip arp-security convert

ipv6 nd-security convert

Change dynamic ARP, ND to static ARP, ND.

Advertising