Table 174: Dynamic ARP Inspection VLAN Configuration
Field
Description
VLAN ID
Lists each VLAN that has been enabled for DAI. After you click
Add
, use the VLAN ID menu to
select the VLAN on which to enable DAI. A VLAN does not need to exist on the system to be
enabled for DAI.
Logging Invalid
Packets
Whether DAI logging is enabled on this VLAN. When logging is enabled, DAI generates a log
message whenever an invalid ARP packet is discovered and dropped.
ARP ACL Name
The name of the of ARP
that the VLAN uses as the filter for ARP
packet validation. The ARP ACL must already exist on the system to associate it with a DAI-
enabled VLAN. ARP ACLs include permit rules only.
Static
Determines whether to use the
snooping database for ARP packet validation if the
packet does not match any ARP ACL rules. The options are as follows:
•
Enable – The ARP packet will be validated by the ARP ACL rules only. Packets that do not
match any ARP ACL rules are dropped without consulting the DHCP snooping database.
•
Disable – The ARP packet needs further validation by using the entries in the DHCP
Snooping database.
•
Click
Submit
to apply the new configuration and cause the change to take effect. These changes will
not be retained across a power cycle unless a Save configuration is performed.
•
Click
Refresh
to refresh the page with the most current data from the switch.
DAI Interface Configuration
Use the DAI Interface Configuration page to select the DAI Interface for which information is to be
displayed or configured.
To display this page, click
Switching
>
Dynamic ARP Inspection
>
Interface Configuration
in the
navigation menu.
Table 175: Dynamic ARP Inspection Interface Configuration
Field
Description
Interface
The interface associated with the rest of the data in the row. In the Edit Interface
Configuration window, this field identifies the interface that is being configured.
Trust State
Whether the DAI feature should check traffic on the interface for possible ARP packet
violations. Trust state can be enabled or disabled after you select an interface and click
Edit
.
This field has one of the following values:
•
Enabled – The interface is trusted. ARP packets arriving on this interface are forwarded
without DAI validation.
•
Disabled – The interface is not trusted. ARP packets arriving on this interface are
subjected to ARP inspection.
Rate Limit
The maximum rate for incoming ARP packets on the interface, in packets per second (pps). If
the incoming rate exceeds the configured limit, the ARP packets are dropped. Rate limiting
can be enabled or disabled after you select an interface and click
Edit
.
Configuring Switching Information
ExtremeSwitching 200 Series: Administration Guide
184