173
EKI-9500 Series User Manual
4.4.5.4
ACL
Use the Dynamic ARP Inspection ACL Configuration page to configure ARP Access
Control Lists (ACLs). An ARP ACL can contain one or more permit rules. Each rule
contains the IP address and MAC address of a system allowed to send ARP packets.
When an ARP ACL is associated with a DAI-enabled VLAN, and an ARP packet is
received on an interface that is a member of that VLAN, DAI validates the address
information in the ARP packet against the rules in the ACL. If the sender information
in the ARP packet matches a rule in the ARP ACL, DAI considers the packet to be
valid, and the packet is forwarded.
To access this page, click
Switching
>
Dynamic ARP Inspection
>
ACL
.
Figure 4.185 Switching > Dynamic ARP Inspection > ACL
The following table describes the items in the previous figure.
To add a new ARP ACL:
Click
Switching
>
Dynamic ARP Inspection
>
ACL
>
Add ACL
.
Figure 4.186 Switching > Dynamic ARP Inspection > ACL > Add ACL
Burst Interval
The number of consecutive seconds the interface is monitored for
incoming ARP packet rate limit violations.
Refresh
Click
Refresh
to update the screen.
Edit
Click
Edit
to edit the selected entries.
Item
Description
Item
Description
ACL Name
The name of the ACL. Only the ACLs that appear in this column can be
referenced by DNI-enabled VLANs. When adding a rule to an existing
ACL, use the ACL Name menu to select the ACL to update.
Sender IP Address
The IP address of a system that is permitted to send ARP packets. The
ARP packet must match on both the Sender IP Address and Sender
MAC Address values in the rule to be considered valid.
Sender MAC
Address
The MAC address of a system that is permitted to send ARP packets.
The ARP packet must match on both the Sender IP Address and
Sender MAC Address values in the rule to be considered valid.
Refresh
Click
Refresh
to update the screen.
Add ACL
Click
Add ACL
to add a new ARP ACL.
Add Rule
Click
Add Rule
to add a new rule to an existing ACL.
Remove
Click
Remove
to remove the selected entries.