disable iparp gratuitous protect vlan

disable iparp gratuitous protect [ {vlan} vlan_name | vlan vlan_list]

Description

Disables gratuitous ARP protection on the specified VLAN.

Syntax Description

vlan_name Specifies the VLAN.
vlan_list Specifies a VLAN list of IDs.

Default

Disabled.

Usage Guidelines

Hosts can launch man-in-the-middle attacks by sending out gratuitous ARP requests for the router's IP address. This results in hosts sending their router traffic to the attacker, and the attacker forwarding that data to the router. This allows passwords, keys, and other information to be intercepted.

To protect against this type of attack, the router will send out its own gratuitous ARP request to override the attacker whenever a gratuitous ARP broadcast with the router's IP address as the source is received on the network.

This command disables gratuitous ARP protection.

Example

The following example disables gratuitous ARP protection for VLAN corp:

disable iparp gratuitous protect vlan corp

History

This command was first available in ExtremeXOS 11.2.

The vlan_list option was added in ExtremeXOS 16.1.

Platform Availability

This command is available on BlackDiamond X8 series switches, BlackDiamond 8000 series modules, and Summit Family switches.