INS_CWGE24MS2_REV–
10/05/16 PAGE 212
INSTALLATION AND OPERATION MANUAL
CWGE24MS2
TECH SUPPORT: 1.888.678.9427
ARP Inspection
ARP Inspection
Introduction
Dynamic ARP inspection is a security feature which validates ARP packet in a network by
performing IP to MAC address binding inspection. Those will be stored in a trusted database (the
DHCP snooping database) before forwarding. Dynamic ARP intercepts, logs, and discards ARP
packets with invalid IP-to-MAC address bindings. This capability protects the network from certain
man-in-the-middle attacks.
Dynamic ARP inspection ensures that only valid ARP requests and responses are relayed. The
switch performs these activities:
» Intercepts all ARP requests and responses on untrusted ports.
» Verifies that each of these intercepted packets has a valid IP-to-MAC address binding before it
updates the local ARP cache or before it forwards the packet to the appropriate destination.
Trusted and untrusted port
» This setting is independent of the trusted and untrusted setting of the DHCP Snooping.
» The Switch does not discard ARP packets on trusted ports for any reasons.
» The Switch discards ARP packets on un-trusted ports if the sender’s information in the ARP
packets does not match any of the current bindings.
» Normally, the trusted ports are the uplink port and the untrusted ports are connected to
subscribers.
Configurations:
Users can enable/disable the ARP Inspection on the Switch. Users also can enable/disable the ARP
Inspection on a specific VLAN. If the ARP Inspection on the Switch is disabled, the ARP Inspection
is disabled on all VLANs even some of the VLAN ARP Inspection are enabled.