Operation Manual – ARP
H3C S5100-SI/EI Series Ethernet Switches
Chapter 1 ARP Configuration
1-7
To do…
Use the command…
Remarks
Enable the ARP entry
checking function (that is,
disable the switch from
learning ARP entries with
multicast MAC
addresses)
arp check enable
Optional
Enabled by default.
Caution:
z
Static ARP entries are valid as long as the Ethernet switch operates normally. But
some operations, such as removing a VLAN, or removing a port from a VLAN, will
make the corresponding ARP entries invalid and therefore removed automatically.
z
As for the
arp static
command, the value of the
vlan-id
argument must be the ID of
an existing VLAN, and the port identified by the
interface-type
and
interface-number
arguments must belong to the VLAN.
z
Currently, static ARP entries cannot be configured on the ports of an aggregation
group.
1.2.2 Configuring ARP Attack Detection
Follow these steps to configure the ARP attack detection function:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Create a static binding
ip source static binding
ip-address
ip-address
[
mac-address
mac-address
]
Enable DHCP
snooping
dhcp-snooping
Required
Use at least one of the
commands.
By default, no IP static
binding is created, and the
DHCP snooping function is
disabled.
Enter Ethernet port
view
interface
interface-type
interface-number
—
Specify the current port
as a trusted port
dhcp-snooping trust
Optional
After DHCP snooping is
enabled, you need to
configure the upstream port
connected to the DHCP
server as a trusted port.