ARP£¨Address Resolution Protocol£¬µØÖ·½âÎöÐÒ飩£¬Ä¿µÄÊÇʵÏÖIPµØÖ·µ½MACµØÖ·µÄÓ³Éä¡£¶øÔÚTCP/IPÐÒéÕ»ÖУ¬×î²»°²È«µÄÐÒ飬¿ÉÄÜ·ÇARPĪÊôÁË¡£ÎÒÃǾ³£Ìýµ½µÄÕâЩÊõÓ°üÀ¨\ÍøÂçɨÃè\¡¢\ÄÚÍøÉøÍ¸\¡¢\ÖмäÈËÀ¹½Ø\¡¢\¾ÖÓòÍøÁ÷¿Ø\¡¢\Á÷Á¿ÆÛÆ\£¬»ù±¾¶¼¸úARPÍѲ»Á˸Éϵ¡£±¾ÎÄÖØµãÕë¶ÔÔÚIPv4»·¾³ÏµÄARP·ÀÓùÎÊÌâÒÔ¼°½â¾ö·½°¸½øÐоßÌå²ûÊö¡£Ö÷Òª°üÀ¨£ºARPÆÛƹ¥»÷ÒÔ¼°½â¾ö·½°¸¡¢ARP·ººé¹¥»÷ÒÔ¼°½â¾ö·½°¸ºÍʵ¼Ê²¿ÊðʱµÄ½¨Òé¡£
ARP¹¥»÷½éÉÜ
ARPÆÛƹ¥»÷ ? ARPÆÛƵÄÔÀí
Õý³£µÄARPͨѶ¹ý³ÌÖ»Ðè¹ã²¥ARP RequestºÍµ¥²¥ARP ReplyÁ½¸ö¹ý³Ì£¬¼òµ¥µÄ˵¾ÍÊÇÒ»ÎÊÒ»´ð¡£¶øARPµÄÆÛƾÍÊÇͨ¹ýαÔìÇëÇó»òÕßÓ¦´ð±¨ÎÄÐÎ³ÉµÄÆÛÆ¡£ ? ARPÆÛƹ¥»÷µÄ·ÖÀà
¸ù¾ÝARPÆÛÆÕßÓë±»ÆÛÆÕßÖ®¼ä½ÇÉ«¹ØÏµµÄ²»Í¬£¬Í¨³£¿ÉÒÔ°ÑARPÆÛƹ¥»÷·ÖΪÈçÏÂÁ½ÖÖ£¬Èçͼ1Ëùʾ£º
Ö÷»úÐÍARPÆÛÆ£ºÆÛÆÕßÖ÷»úð³äÍø¹ØÉ豸¶ÔÆäËûÖ÷»ú½øÐÐÆÛÆ¡£ Íø¹ØÐÍARPÆÛÆ£ºÆÛÆÕßÖ÷»úð³äÆäËûÖ÷»ú¶ÔÍø¹ØÉ豸½øÐÐÆÛÆ¡£
¡øÍ¼1 ARPÆÛÆ·ÖÀà
ARP·ººé¹¥»÷ ? ARP·ººé¹¥»÷µÄÔÀí
ARP·ººé¹¥»÷£¬Ò²½Ð¾Ü¾ø·þÎñ¹¥»÷£¨Denial of Service£©£¬¿ÉÄܵ¼Ö´óÁ¿ÏûºÄ½»»»»úÄÚ´æ¡¢±íÏî»òÕ߯äËü×ÊÔ´£¬Ê¹ÏµÍ³ÎÞ·¨¼ÌÐø·þÎñ¡£´óÁ¿µÄ±¨ÎÄÔÒÏòCPU£¬Õ¼ÓÃÁËÕû¸öËÍCPU±¨ÎĵĴø¿í£¬µ¼ÖÂÕý³£µÄÐÒ鱨Îĺ͹ÜÀí±¨ÎÄÎÞ·¨±»CPU´¦Àí£¬´øÀ´ÐÒéÕðµ´»òÕßÉ豸ÎÞ·¨¹ÜÀí£¬½ø¶øµ¼ÖÂÊý¾ÝÃæ×ª·¢ÊÜÓ°Ï죬²¢ÒýÆðÕû¸öÍøÂçÎÞ·¨Õý³£ÔËÐС£
ARPÆÛƹ¥»÷½â¾ö·½°¸
ÔÚ½éÉܾßÌå½â¾ö·½°¸Ö®Ç°£¬ÎÒÃÇÏÈÁ˽âÏ·ÀARPÆÛƵĺËÐŦÄÜ£ºARP-check£¨ARP±¨ÎĺϹæÐ£Ñ飩£¬Ð£ÑéARP±¨ÎĵÄÔ´IPÓ밲ȫµØÖ·ÖеÄIPÊÇ·ñÒ»Ö£¬Ð£ÑéARP±¨ÎĵÄÔ´MACÓ밲ȫµØÖ·ÖеÄMACÊÇ·ñÒ»Ö£¬ÔÚÁ½ÏîУÑé¾ùºÏ¹æµÄÇé¿ö϶Ա¨ÎĽøÐÐת·¢¡£¶ø°²È«µØÖ·µÄÉú³É£¬ÎÒÃÇ¿ÉÒÔͨ¹ýÊÖ¹¤¾²Ì¬°ó¶¨µÄ·½Ê½ÒÔ¼°DHCP Snooping¼à²âµÄ·½Ê½»ñÈ¡£¬¾ßÌåÁ÷³ÌÈçͼ2£º
¡øÍ¼2 ARP-checkÁ÷³Ì
ÒÔÉÏÊÇÓ²¼þ¼ì²âµÄÁ÷³Ì£¬³ý´ËÖ®Í⻹ÓÐÒ»ÖÖÈí¼þУÑéµÄ·½Ê½£¬¾ÍÊǽ«¶Ë¿ÚµÄARPÇëÇóÖ±½ÓËÍÍùCPU£¬¶øCPUÒÀ¾ÝDHCP SnoopingµÄ±íÏî½øÐкϹæ¼ì²é¡£ ¶Ë¿Ú°²È« + ARP-check·½°¸
Ó¦Óó¡¾°£º´Ë·½°¸ÊÊÓÃÓÚÓû§IPµØÖ·Îª¾²Ì¬·ÖÅäµÄ³¡¾°£¬²¢ÇÒÐèÒªÃ÷È·ÖªµÀÿ¸öÓû§ËùÁ¬½Ó½»»»»ú¶Ë¿Ú¡£
¹¦Äܼò½é£ºÍ¨¹ýÊÖ¹¤µÄ·½Ê½½«IPÓëMACµÄ¶ÔÓ¦¹ØÏµÅäÖõ½½»»»»úµÄ¶Ë¿Ú£¬²¢¿ªÆôARPºÏ¹æ¼ì²é¡£¾ßÌåÅäÖÃÈçͼ3£º
¡øÍ¼3 ¶Ë¿Ú°²È«+ARP-check·½°¸ÅäÖÃ
·½°¸µÄÓÅÊÆ£º¿ØÖƷdz£Ñϸñ£¬Ó¦ÓÃÓ²¼þ·½Ê½Ö±½ÓУÑéARP±¨ÎÄ£¬×¼È·£¬ÎÞÐèÏûºÄCPU¡£ ȱµãµÄÁÓÊÆ£º¶Ë¿Ú°²È«±ØÐëÊÕ¼¯²¢ÅäÖÃËùÓÐÓû§IPºÍMACÐÅÏ¢£¬½ÏΪ·±ÔÓ£¬²»¹»Áé»î£¬²»ÊʺÏÓÚÓû§ÐèҪƵ·±Ç¨Òƶ˿ڵĻ·¾³¡£ È«¾ÖIP&MAC°ó¶¨+ARP-check·½°¸
Ó¦Óó¡¾°£º´Ë·½°¸ÊÊÓÃÓÚÓû§IPµØÖ·Îª¾²Ì¬·ÖÅäµÄ³¡¾°£¬µ«¹ÜÀíÔ±²»ÐèÒªÖªµÀÿ¸öÓû§ËùÁ¬½ÓµÄ½»»»»ú¶Ë¿Ú£¬Òò´ËÊÊÓÃÓÚÓû§·Ö²¼Çé¿ö²»È·¶¨£¬»òÕßÏÂÁªÓû§´æÔÚËæÒâÒÆ¶¯¶Ë¿ÚµÄ³¡¾°ÖС£
¹¦Äܼò½é£ºÍ¨¹ýÊÖ¹¤·½Ê½½«IPÓëMACµÄ¶ÔÓ¦¹ØÏµÅäÖõ½½»»»»úÈ«¾Ö£¬²¢ÔÚ½»»»»úµÄ¶Ë¿ÚÏ¿ªÆôARPºÏ¹æ¼ì²é¡£¾ßÌåÅäÖÃÈçͼ4£º
¡øÍ¼4 È«¾ÖIP+MAC°ó¶¨+ARP-check·½°¸ÅäÖÃ
·½°¸µÄÓŵ㣺¿ØÖƽÏΪÑϸñ£¬ÔÊÐíÓû§ÔÚ±¾½»»»»úÄÚ²¿½øÐж˿ÚÇ¨ÒÆ¾ß±¸Ò»¶¨µÄÁé»îÐÔ£¬Ó¦ÓÃÓ²¼þ·½Ê½Ö±½ÓУÑéARP±¨ÎÄ£¬×¼È·£¬ÎÞÐèÏûºÄCPU¡£
·½°¸µÄȱµã£º¶Ë¿Ú°²È«±ØÐëÊÕ¼¯²¢ÅäÖÃËùÓÐÓû§IPºÍMACÐÅÏ¢£¬½ÏΪ·±ÔÓ¡£
DAI·½°¸
Ó¦Óó¡¾°£ºDAI£¨Dynamic ARP Inspection£©·½°¸ÊʺÏÓÚ½ÓÈëÓû§Ê¹ÓÃDHCP¶¯Ì¬»ñÈ¡IPµØÖ·»·¾³£¬Í¬Ê±ÒªÇó²¿ÊðDHCP Snooping¹¦ÄÜ¡£
¹¦Äܼò½é£ºÌáÈ¡DHCP Snooping±íÖеÄIP+MACÐÅÏ¢£¬Í¨¹ýCPU¹ýÂËÔ´MAC/Ô´IP²»ÔÚSnooping±íÖеÄARP±¨ÎÄ£¬¾ßÌåÁ÷³ÌÈçͼ5£º
¡øÍ¼5 DAI·½°¸ARPºÏ¹æ¼ì²éÁ÷³Ìͼ ¾ßÌåÅäÖüûͼ6£º
¡øÍ¼6 DAI·½°¸ÅäÖÃ
·½°¸µÄÓŵ㣺ÅäÖÃά»¤¼òµ¥£¬ÎÞÐèÊÖ¹¤ÅäÖÃÿ¸öÓû§µÄIP&MAC°ó¶¨¡£
·½°¸µÄȱµã£ºÓÉÓÚÓû§µÄARP±¨ÎÄËÍCPU¼ì²é£¬¼ì²éµÄÀ´Ô´ÊÇDHCP SnoopingËù¼Ç¼µÄÈí¼þ±íÏÒò´Ë»á¶îÍâÏûºÄÉ豸µÄCPU×ÊÔ´¡£ IP Source Guard + ARP-check·½°¸
Ó¦Óó¡¾°£º´Ë·½°¸ÊʺÏÓÚ½ÓÈëÓû§Ê¹ÓÃDHCP¶¯Ì¬»ñÈ¡IPµØÖ·»·¾³£¬Í¬Ê±ÒªÇó²¿ÊðDHCP Snooping¹¦ÄÜ ¡£
¹¦Äܼò½é£ºÌáÈ¡DHCP Snooping±íÖÐÕýÈ·µÄIPÓëMAC£¬Í¨¹ýIP Source Guard½«DHCP Snooping±íдÈë½»»»»úÓ²¼þ±íÏʹÓÃARP-check¹¦ÄÜУÑéARP±¨ÎĵĺϷ¨ÐÔ£¬¾ßÌåÁ÷³ÌÈçͼ7£º
¡øÍ¼7 IP Source Guard + ARP-check·½°¸Á÷³Ìͼ ¾ßÌåÅäÖÃÈçͼ8£º
¡øÍ¼8 IP Source Guard + ARP-check·½°¸ÅäÖÃ
·½°¸µÄÓŵ㣺ÅäÖÃά»¤¼òµ¥£¬ºÍDAIÏà±È£¬ARP-checkÊôÓÚÓ²¼þоƬ¼ì²é°²È«±íÏ²»ÏûºÄCPU×ÊÔ´¡£
Ïà¹ØÍÆ¼ö£º