20-5
Cisco ME 3400 Ethernet Access Switch Software Configuration Guide
OL-9639-07
Chapter 20 Configuring Dynamic ARP Inspection
Configuring Dynamic ARP Inspection
Configuring Dynamic ARP Inspection
•
Default Dynamic ARP Inspection Configuration, page 20-5
•
Dynamic ARP Inspection Configuration Guidelines, page 20-5
•
Configuring Dynamic ARP Inspection in DHCP Environments, page 20-7
(required in DHCP
environments)
•
Configuring ARP ACLs for Non-DHCP Environments, page 20-8
(required in non-DHCP
environments)
•
Limiting the Rate of Incoming ARP Packets, page 20-10
(optional)
•
Performing Validation Checks, page 20-11
(optional)
•
Configuring the Log Buffer, page 20-12
(optional)
Default Dynamic ARP Inspection Configuration
Table 20-1
shows the default dynamic ARP inspection configuration.
Dynamic ARP Inspection Configuration Guidelines
•
Dynamic ARP inspection is an ingress security feature; it does not perform any egress checking.
Table 20-1
Default Dynamic ARP Inspection Configuration
Feature
Default Setting
Dynamic ARP inspection
Disabled on all VLANs.
Interface trust state
All interfaces are untrusted.
Rate limit of incoming ARP packets
The rate is 15 pps on untrusted interfaces, assuming that
the network is a switched network with a host
connecting to as many as 15 new hosts per second.
The rate is unlimited on all trusted interfaces.
The burst interval is 1 second.
ARP ACLs for non-DHCP environments
No ARP ACLs are defined.
Validation checks
No checks are performed.
Log buffer
When dynamic ARP inspection is enabled, all denied or
dropped ARP packets are logged.
The number of entries in the log is 32.
The number of system messages is limited to 5 per
second.
The logging-rate interval is 1 second.
Per-VLAN logging
All denied or dropped ARP packets are logged.
Summary of Contents for ME 3400 Series
Page 40: ...Contents xl Cisco ME 3400 Ethernet Access Switch Software Configuration Guide OL 9639 07 ...
Page 44: ...xliv Cisco ME 3400 Ethernet Access Switch Software Configuration Guide OL 9639 07 Preface ...
Page 1138: ...Index IN 52 Cisco ME 3400 Ethernet Access Switch Software Configuration Guide OL 9639 07 ...