To defend against ARP attacks, a switch must be able to identify and read ARP packets, determine whether there is any Spoofing Attack Based on the packets, and discard ARP spoofing packets.
The access layer uses the ARP Intrusion Inspection function of the access switch to defend against ARP spoofing attacks.
ARP intrusion detection is deployed on the access switch. The access switch also enables DHCP Snooping to monitor DHCP packets. DHCP Snooping records the user's IP, MAC, VLAN, and PORT information by monitoring DHCP packets, and forms a DHCP Snooping binding table. After receiving the ARP packet, the switch port searches for the binding relationship table established by DHCP Snooping to determine whether the source IP address and source MAC address of the ARP response packet are valid. If the source MAC address and IP address of the sender in the ARP packet match the content in the binding table, it is regarded as a valid packet and allowed to pass. Otherwise, it is considered as a spoofing attack packet and discarded.
ARP intrusion detection can prevent access terminals from initiating any ARP spoofing attacks. If the AII function is deployed across the network, ARP spoofing attacks can be effectively solved.
In addition, due to ARP spoofing attacks, followers often send a large number of ARP packets, consuming network bandwidth resources and switch CPU resources, reducing the network speed. Therefore, the access switch also needs to deploy the ARP packet speed limit to limit the ARP packets received by each port within the unit time, which ensures the network bandwidth resources and the switch CPU resources.
- Anti-ARP for Internet cafe switches in converged Networks
- Configuration case of Huawei switches Preventing ARP spoofing attacks in the same network segment