H3C Low-End Ethernet Switches Configuration ExamplesARP Attack Prevention Chapter 2 Configuration Examples2-22.1.2 Network DiagramIP networkSwitch A Swtich BGatewayDHCP serverEth1/0/1Eth1/0/3TFTP serverIP:192.168.0.10/24Eth1/0/3Eth1/0/1Vlan-int 10192.168.0.1/24Eth1/0/1Host A Host CVlan-int 20192.168.1.1/24Eth1/0/2Eth1/0/4 Eth1/0/2Host BEth1/0/3Eth1/0/4 Eth1/0/2Host EHost DVLAN10Host area1VLAN20Host area2Figure 2-1 Network diagram for ARP attack prevention in DHCP snooping mode2.1.3 Configuration Considerationsz Enable DHCP snooping on Switch A and Switch B, and configure their portsconnected to the DHCP server as a DHCP snooping trusted port.z Configure an IP static binding entry for the TFTP server on Switch A.z Enable ARP attack detection on VLAN 10 of Switch A and VLAN 20 of Switch Brespectively, and configure their uplink ports as ARP trusted ports.z Configure ARP packet rate limit on the ports which directly connected to hosts ofSwitch A and Switch B, and enable the port state auto-recovery function globallyon the two switches.2.1.4 Configuration ProceduresI. Software version usedThis example is configured and verified on S3100-EI series Ethernet switchesRelease2104.