PowerConnect B-Series FCX Configuration Guide
1347
53-1002266-01
Dynamic ARP inspection
39
•
DHCP-Snooping ARP – information collected from snooping DHCP packets when DHCP
snooping is enabled on VLANs.
The status of an ARP entry is either pending or valid:
•
Valid – the mapping is valid, and the port is resolved. This is always the case for static ARP
entries.
•
Pending – for normal dynamic and inspection ARP entries before they are resolved, and the
port mapped. Their status changes to valid when they are resolved, and the port mapped.
Refer to also
“System reboot and the binding database”
on page 1351.
Configuration notes and feature limitations
The following limits and restrictions apply when configuring DAI:
•
To run Dynamic ARP Inspection, you must first enable support for ACL filtering based on VLAN
membership or VE port membership. To do so, enter the following commands at the Global
CONFIG Level of the CLI.
PowerConnect(config)#enable ACL-per-port-per-vlan
PowerConnect(config)#write memory
PowerConnect(config)#exit
PowerConnect#reload
NOTE
You must save the configuration and reload the software to place the change into effect.
•
Dell recommends that you do not enable DAI on a trunk port.
•
The maximum number of DHCP and static DAI entries depends on the maximum number of
ARP table entries allowed on the device. A Layer 2 switch can have up to 256 ARP entries and
a Layer 3 switch can have up to 64,000 ARP entries. In a Layer 3 switch, you can use the
system-max ip-arp command to change the maximum number of ARP entries for the device.
However, only up to 1024 DHCP entries can be saved to flash.
•
ACLs are supported on member ports of a VLAN on which DHCP snooping and Dynamic ARP
Inspection (DAI) are enabled.
•
DAI is supported on a VLAN without a VE, or on a VE with or without an assigned IP address.
Configuring DAI
Configuring DAI consists of the following steps.
1. Configure inspection ARP entries for hosts on untrusted ports.Refer to
“Configuring an
inspection ARP entry”
on page 1348.
2. Enable DAI on a VLAN to inspect ARP packets.Refer to
“Enabling DAI on a VLAN”
on page 1348.
3. Configure the trust settings of the VLAN members. ARP packets received on
trusted
ports
bypass the DAI validation process. ARP packets received on
untrusted
ports go through the
DAI validation process.Refer to
“Enabling trust on a port”
on page 1348.
4. Enable DHCP snooping to populate the DHCP snooping IP-to-MAC binding database.
The following shows the default settings of DAI.
Summary of Contents for PowerConnect B-FCXs
Page 1: ...53 1002266 01 18 March 2011 PowerConnect B Series FCX Configuration Guide ...
Page 248: ...206 PowerConnect B Series FCX Configuration Guide 53 1002266 01 IPv6 management commands 7 ...
Page 374: ...332 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Jumbo frame support 9 ...
Page 568: ...526 PowerConnect B Series FCX Configuration Guide 53 1002266 01 CLI examples 14 ...
Page 588: ...546 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Sample application 15 ...
Page 684: ...642 PowerConnect B Series FCX Configuration Guide 53 1002266 01 VLAN based mirroring 20 ...
Page 724: ...682 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Reading CDP packets 23 ...
Page 930: ...888 PowerConnect B Series FCX Configuration Guide 53 1002266 01 26 ...
Page 948: ...906 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Configuring MLD snooping 27 ...
Page 1348: ...1306 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Example configurations 36 ...
Page 1406: ...1364 PowerConnect B Series FCX Configuration Guide 53 1002266 01 IP source guard 39 ...