113
Dynamic ARP Inspection Commands
its unsuspecting neighbors. The miscreant sends ARP requests or responses mapping another station’s IP address to its
own MAC address.
DAI relies on DHCP snooping. DHCP snooping listens to DHCP message exchanges and builds a binding database of valid
{MAC address, IP address, VLAN, and interface} tuples.
When DAI is enabled, the switch drops ARP packets whose sender MAC address and sender IP address do not match an
entry in the DHCP snooping bindings database. You can optionally configure additional ARP packet validation.
ip arp inspection vlan
Use this command to enable Dynamic ARP Inspection on a list of comma-separated VLAN ranges.
no ip arp inspection vlan
Use this command to disable Dynamic ARP Inspection on a list of comma-separated VLAN ranges.
ip arp inspection validate
Use this command to enable additional validation checks like source-mac validation, destination-mac validation, and ip
address validation on the received ARP packets. Each command overrides the configuration of the previous command. For
example, if a command enables src-mac and dst-mac validations, and a second command enables IP validation only, the
src-mac and dst-mac validations are disabled as a result of the second command.
no ip arp inspection validate
Use this command to disable the additional validation checks on the received ARP packets.
ip arp inspection vlan logging
Use this command to enable logging of invalid ARP packets on a list of comma-separated VLAN ranges.
Default
disabled
Format
ip arp inspection vlan vlan-list
Mode
Global Config
Format
no ip arp inspection vlan vlan-list
Mode
Global Config
Default
disabled
Format
ip arp inspection validate {[src-mac] [dst-mac] [ip]}
Mode
Global Config
Format
no ip arp inspection validate {[src-mac] [dst-mac] [ip]}
Mode
Global Config
Summary of Contents for DWS-4000 Series
Page 20: ...D Link Unified Switch CLI Command Reference 12 2009 D Link Corporation All Rights Reserved ...
Page 170: ...D Link Unified Switch CLI Command Reference 162 2009 D Link Corporation All Rights Reserved ...
Page 369: ...361 Captive Portal Status Commands Locale Link The names of the languages Field Description ...
Page 416: ...D Link Unified Switch CLI Command Reference 408 2009 D Link Corporation All Rights Reserved ...
Page 528: ...D Link Unified Switch CLI Command Reference 520 2009 D Link Corporation All Rights Reserved ...
Page 545: ...537 O SSupport ...
Page 546: ...D Link Unified Switch CLI Command Reference 538 2009 D Link Corporation All Rights Reserved ...
Page 566: ...D Link Unified Switch CLI Command Reference 558 2009 D Link Corporation All Rights Reserved ...