Purpose
Command or Action
Returns to global configuration mode.
exit
Step 5
Applies ARP ACL to the VLAN. By default, no defined ARP ACLs are applied
to any VLAN.
ip arp inspection filter arp-acl-name
vlan vlan-range
[
static
]
Step 6
•
For
arp-acl-name
, specify the name of the ACL created in Step 2.
•
For
vlan-range
, specify the VLAN that the switches and hosts are in.
You can specify a single VLAN identified by VLAN ID number, a range
of VLANs separated by a hyphen, or a series of VLANs separated by a
comma. The range is 1 to 4094.
•
(Optional) Specify
static
to treat implicit denies in the ARP ACL as
explicit denies and to drop packets that do not match any previous clauses
in the ACL. DHCP bindings are not used.
If you do not specify this keyword, it means that there is no explicit deny
in the ACL that denies the packet, and DHCP bindings determine whether
a packet is permitted or denied if the packet does not match any clauses
in the ACL.
ARP packets containing only IP-to-MAC address bindings are compared
against the ACL. Packets are permitted only if the access list permits them.
Specifies Switch A interface that is connected to Switch B, and enters the
interface configuration mode.
interface interface-id
Step 7
Configures Switch A interface that is connected to Switch B as untrusted.
no ip arp inspection trust
Step 8
By default, all interfaces are untrusted.
For untrusted interfaces, the switch intercepts all ARP requests and responses.
It verifies that the intercepted packets have valid IP-to-MAC address bindings
before updating the local cache and before forwarding the packet to the
appropriate destination. The switch drops invalid packets and logs them in the
log buffer according to the logging configuration specified with the
ip arp
inspection vlan logging
global configuration command.
Returns to privileged EXEC mode.
end
Step 9
Verifies your entries.
Use the following show commands:
Step 10
•
show arp access-list
acl-name
•
show ip arp inspection vlan
vlan-range
•
show ip arp inspection
interfaces
Consolidated Platform Configuration Guide, Cisco IOS Release 15.2(4)E (Catalyst 2960-X Switches)
1307
Configuring ARP ACLs for Non-DHCP Environments
Summary of Contents for Catalyst 2960 Series
Page 96: ......
Page 196: ......
Page 250: ......
Page 292: ......
Page 488: ......
Page 589: ...P A R T VI Cisco Flexible NetFlow Configuring NetFlow Lite page 509 ...
Page 590: ......
Page 619: ...P A R T VII QoS Configuring QoS page 539 Configuring Auto QoS page 645 ...
Page 620: ......
Page 750: ......
Page 1604: ......
Page 1740: ......
Page 2105: ...P A R T XII Configuring Cisco IOS IP SLAs Configuring Cisco IP SLAs page 2025 ...
Page 2106: ......
Page 2118: ......
Page 2164: ......