DHCP Snooping Commands
329
OL-32830-01 Command Line Interface Reference Guide
13
13.22 ip arp inspection trust
Use the ip arp inspection trust Interface Configuration (Ethernet, Port-channel)
mode command to configure an interface trust state that determines if incoming
Address Resolution Protocol (ARP) packets are inspected. Use the no form of this
command to restore the default configuration.
Syntax
ip arp inspection trust
no ip arp inspection trust
Parameters
N/A
Default Configuration
The interface is untrusted.
Command Mode
Interface (Ethernet, Port Channel) Configuration mode
User Guidelines
The device does not check ARP packets that are received on the trusted interface;
it only forwards the packets.
For untrusted interfaces, the device intercepts all ARP requests and responses. It
verifies that the intercepted packets have valid IP-to-MAC address bindings
before updating the local cache and before forwarding the packet to the
appropriate destination. The device drops invalid packets and logs them in the log
buffer according to the logging configuration specified with the
ip arp inspection
logging interval
command.
Example
The following example configures
gi1
3 as a trusted interface.
switchxxxxxx(config)#
interface
gi1
3
switchxxxxxx(config-if)#
ip arp inspection trust
Summary of Contents for 300 Series
Page 2: ......