C
HAPTER
25
| General Security Measures
ARP Inspection
– 675 –
ip arp inspection
filter
This command specifies an ARP ACL to apply to one or more VLANs. Use
the
no
form to remove an ACL binding.
S
YNTAX
ip arp inspection filter
arp-acl-name
vlan
{
vlan-id
|
vlan-range
}
[
static
]
arp-acl-name - Name of an ARP ACL.
(Maximum length: 16 characters)
vlan-id
- VLAN ID. (Range: 1-4093)
vlan-range
- A consecutive range of VLANs indicated by the use a
hyphen, or a random group of VLANs with each entry separated by
a comma.
static
- ARP packets are only validated against the specified ACL,
address bindings in the DHCP snooping database is not checked.
D
EFAULT
S
ETTING
ARP ACLs are not bound to any VLAN
Static mode is not enabled
C
OMMAND
M
ODE
Global Configuration
C
OMMAND
U
SAGE
◆
ARP ACLs are configured with the commands described on
page 310
.
◆
If static mode is enabled, the switch compares ARP packets to the
specified ARP ACLs. Packets matching an IP-to-MAC address binding in
a permit or deny rule are processed accordingly. Packets not matching
any of the ACL rules are dropped. Address bindings in the DHCP
snooping database are not checked.
◆
If static mode is not enabled, packets are first validated against the
specified ARP ACL. Packets matching a deny rule are dropped. All
remaining packets are validated against the address bindings in the
DHCP snooping database.
E
XAMPLE
Console(config)#ip arp inspection filter sales vlan 1
Console(config)#
Summary of Contents for ES3510MA
Page 1: ...Management Guide www edge core com 8 Port Layer 2 Fast Ethernet Switch...
Page 4: ...ABOUT THIS GUIDE 4...
Page 30: ...CONTENTS 30...
Page 40: ...FIGURES 40...
Page 46: ...TABLES 46...
Page 48: ...SECTION I Getting Started 48...
Page 72: ...SECTION II Web Configuration 72...
Page 88: ...CHAPTER 3 Using the Web Interface Navigating the Web Browser Interface 88...
Page 116: ...CHAPTER 4 Basic Management Tasks Resetting the System 116...
Page 154: ...CHAPTER 5 Interface Configuration VLAN Trunking 154...
Page 216: ...CHAPTER 8 Spanning Tree Algorithm Configuring Interface Settings for MSTP 216...
Page 350: ...CHAPTER 14 Security Measures DHCP Snooping 350...
Page 440: ...CHAPTER 17 IP Services Displaying the DNS Cache 440...
Page 484: ...CHAPTER 19 Using the Command Line Interface CLI Command Groups 484...
Page 554: ...CHAPTER 21 System Management Commands Switch Clustering 554...
Page 574: ...CHAPTER 22 SNMP Commands 574...
Page 582: ...CHAPTER 23 Remote Monitoring Commands 582...
Page 636: ...CHAPTER 24 Authentication Commands Management IP Filter 636...
Page 736: ...CHAPTER 29 Port Mirroring Commands RSPAN Mirroring Commands 736...
Page 816: ...CHAPTER 34 VLAN Commands Configuring Voice VLANs 816...
Page 830: ...CHAPTER 35 Class of Service Commands Priority Commands Layer 3 and 4 830...
Page 848: ...CHAPTER 36 Quality of Service Commands 848...
Page 900: ...CHAPTER 38 LLDP Commands 900...
Page 910: ...CHAPTER 39 Domain Name Service Commands 910...
Page 916: ...CHAPTER 40 DHCP Commands DHCP Client 916...
Page 948: ...CHAPTER 41 IP Interface Commands IPv6 Interface 948...
Page 950: ...SECTION IV Appendices 950...
Page 982: ...INDEX 982...
Page 983: ......