2.3 Disable the Proxy ARP Function - d) No local-proxy-arp

Information

PROXY ARP should be used in networks where the host is not configured with default gateway or there is no routing policy.

PROXY ARP has negative effects:
1. ARP traffic on one network segment is increased
2. The host needs a larger ARP table to process the mapping from IP address to MAC address
3. Security problems are available, such as ARP spoofing (spoofing)
4. Does not work for a network that does not use ARP to parse addresses
5. Network topology cannot be summarized and promoted

Note: The default setting of proxy arp is disabled

Solution

Disable the functions related to Proxy ARP:

ZXR10 (config)#arp
ZXR10 (config-arp)#interface fei-0/1/1/13
ZXR10 (config-arp-if)#no proxy
ZXR10 (config-arp-if)#no inter-vlan-proxy
ZXR10 (config-arp-if)#no proxy local
ZXR10 (config-arp-if)#no local-proxy-arp

See Also

https://support.zte.com.cn/support/doccenter/DocumentProductHandBookDetail.aspx?sid=102&id=30768582&type=docfeedback

Item Details

Audit Name: Tenable ZTE ROSNG

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: ZTE_ROSNG

Control ID: 33c43621793d310addd454217d97154b077ba517613ce4e0fc048d79d9640676