Configuring Security
Configuring Dynamic ARP Inspection
Cisco 220 Series Smart Switches Administration Guide Release 1.1.0.x
230
16
Configuring ARP Inspection Trusted Interfaces
Use the Interface Settings page to define trusted and untrusted interfaces. These
settings are independent to the trusted interface settings defined for DHCP
Snooping. ARP Inspection is enabled only on untrusted interfaces.
To change the ARP trusted status of an interface:
STEP 1
Click
Security
>
ARP Inspection
>
Interface Settings
.
STEP 2
Select the interface type (Port or LAG), and click
Go
.
STEP 3
Select an interface, and click
Edit
.
STEP 4
Enter the following information:
•
Interface
—Select a port or LAG on which ARP Inspection trust mode can be
enabled.
•
Trusted Interface
—Click
Yes
to enable ARP Inspection trust mode on the
interface, or click
No
to disable ARP Inspection trust mode on the interface.
-
If enabled, the port or LAG is a trusted interface, and ARP inspection is
not performed on the ARP requests or replies sent to or from the
interface.
-
If disabled, the port or LAG is not a trusted interface, and ARP inspection
is performed on the ARP requests or replies sent to or from the interface.
By default, it is disabled.
•
Rate Limit (pps)
—Enter the maximum rate that is allowed on the interface.
The range is 1 to 300 pps and the default is 15.
STEP 5
Click
Apply
. The ARP Inspection trusted interfaces are defined, and the Running
Configuration is updated.