415
Configuring Dynamic ARP Inspection
Monitoring and Maintaining Dynamic ARP Inspection
Monitoring and Maintaining Dynamic ARP Inspection
Configuration Examples for Dynamic ARP Inspection
Configuring Dynamic ARP Inspection in DHCP Environments: Example
This example shows how to configure DAI on Switch A in VLAN 1. You would perform a similar procedure on Switch B:
Switch(config)#
ip arp inspection vlan 1
Switch(config)#
interface GigabitEthernet1/17
Switch(config-if)#
ip arp inspection trust
Configuring ARP ACLs for Non-DHCP Environments: Example
This example shows how to configure an ARP ACL called
host2
on Switch A, to permit ARP packets from Host 2 (IP
address 1.1.1.1 and MAC address 0001.0001.0001), to apply the ACL to VLAN 1, and to configure port 1 on Switch A
as untrusted:
Switch(config)#
arp access-list host2
Switch(config-arp-acl)#
permit ip host 1.1.1.1 mac host 1.1.1
Switch(config-arp-acl)#
exit
Switch(config)#
ip arp inspection filter host2 vlan 1
Switch(config)#
interface GigabitEthernet1/17
Switch(config-if)#
no ip arp inspection trust
Additional References
The following sections provide references related to switch administration:
Command
Description
clear ip arp inspection log
Clears the DAI log buffer.
clear ip arp inspection statistics
Clears the DAI statistics.
show arp access-list
[
acl-name
]
Displays detailed information about ARP ACLs.
show errdisable recovery
Displays the error-disabled recovery timer information.
show ip arp inspection interfaces
[
interface-id
]
Displays the trust state and the rate limit of ARP packets for the specified
interface or all interfaces.
show ip arp inspection log
Displays the configuration and contents of the DAI log buffer.
show ip arp inspection vlan
vlan-range
Displays the configuration and the operating state of DAI for the specified
VLAN. If no VLANs are specified or if a range is specified, displays
information only for VLANs with DAI enabled (active).
show ip arp inspection statistics
[
vlan
vlan-range
]
Displays statistics for forwarded, dropped, MAC validation failure, IP
validation failure, ACL permitted and denied, and DHCP permitted and
denied packets for the specified VLAN. If no VLANs are specified or if a
range is specified, displays information only for VLANs with DAI enabled
(active).
show ip dhcp snooping binding
Verifies the DHCP bindings.
Summary of Contents for IE 4000
Page 12: ...8 Configuration Overview Default Settings After Initial Switch Configuration ...
Page 52: ...48 Configuring Interfaces Monitoring and Maintaining the Interfaces ...
Page 108: ...104 Configuring Switch Clusters Additional References ...
Page 128: ...124 Performing Switch Administration Additional References ...
Page 130: ...126 Configuring PTP ...
Page 140: ...136 Configuring CIP Additional References ...
Page 146: ...142 Configuring SDM Templates Configuration Examples for Configuring SDM Templates ...
Page 192: ...188 Configuring Switch Based Authentication Additional References ...
Page 244: ...240 Configuring IEEE 802 1x Port Based Authentication Additional References ...
Page 298: ...294 Configuring VLANs Additional References ...
Page 336: ...332 Configuring STP Additional References ...
Page 408: ...404 Configuring DHCP Additional References ...
Page 450: ...446 Configuring IGMP Snooping and MVR Additional References ...
Page 490: ...486 Configuring SPAN and RSPAN Additional References ...
Page 502: ...498 Configuring Layer 2 NAT ...
Page 770: ...766 Configuring IPv6 MLD Snooping Related Documents ...
Page 930: ...926 Configuring IP Unicast Routing Related Documents ...
Page 976: ...972 Configuring Cisco IOS IP SLAs Operations Additional References ...
Page 978: ...974 Dying Gasp ...
Page 990: ...986 Configuring Enhanced Object Tracking Monitoring Enhanced Object Tracking ...
Page 994: ...990 Configuring MODBUS TCP Displaying MODBUS TCP Information ...
Page 996: ...992 Ethernet CFM ...
Page 1066: ...1062 Using an SD Card SD Card Alarms ...