5000 Series Layer 2/3 Managed Data Center Switch CLI Reference Guide
481
Command Mode
•
Privileged EXEC
•
User EXEC
Example
The following is a CLI display output example.
(Routing)#show ip source binding
MAC Address
IP Address
Type
Vlan
Interface
------------------- ----------
---------------
-----
----------
00:00:00:00:00:08
1.2.3.4
dhcp-snooping
2
0/1
00:00:00:00:00:09
1.2.3.4
dhcp-snooping
3
0/1
00:00:00:00:00:0A
1.2.3.4
dhcp-snooping
4
0/1
Display Parameters
MAC Address
The MAC address for the added entry.
IP Address
The IP address of the added entry.
Type
Entry type definition, static or dynamic.
VLAN
List entry VLAN identifier.
Interface
IP address identifier (slot/port format).
Dynamic ARP Inspection Commands
The Dynamic ARP Inspection (DAI) feature is designed to reject invalid and malicious ARP packets. The
DAI function prevents class of man-in-the-middle attacks.
DAI relies on DHCP snooping, which relies on DHCP message exchanges and builds a binding database
of settings ({MAC address, IP address, VLAN, and interface}.
When enabled, the MAC and sender IP addresses of ARP packets not matching entry in the DHCP
snooping bindings database are dropped.
5-454 ip arp inspection vlan
Enable Dynamic ARP Inspection on a list of comma-separated VLAN ranges.
N
o
command disables Dynamic ARP Inspection on a list of comma-separated VLAN ranges.
ip arp inspection vlan vlan-list
no ip arp inspection vlan vlan-list