1-8
To do…
Use the command…
Remarks
Enable ARP detection for
the VLAN
arp detection enable
Required
Disabled by default. That is, ARP
detection based on static IP Source
Guard binding entries/DHCP snooping
entries/802.1X security entries/OUI MAC
addresses is not enabled by default.
Return to system view
quit
—
Enter Ethernet interface
view
interface interface-type
interface-number
—
Configure the port as a
trusted port on which ARP
detection does not apply
arp detection trust
Optional
The port is an untrusted port by default.
z
When configuring this feature, you need to configure ARP detection based on at least static IP
Source Guard binding entries, DHCP snooping entries, or 802.1X security entries. Otherwise, all
ARP packets received from an ARP untrusted port will be discarded, except the ARP packets with
an OUI MAC address as the sender MAC address when voice VLAN is enabled.
z
When configuring an IP Source Guard binding entry, you need to specify the VLAN; otherwise, no
ARP packet will pass the ARP detection based on static IP Source Guard binding entries.
Displaying and Maintaining ARP Detection
To do…
Use the command…
Remarks
Display the VLANs enabled
with ARP detection
display arp detection
Available in any view
Display the ARP detection
statistics
display arp detection statistics
[
interface
interface-type interface-number
]
Available in any view
Clear the ARP detection
statistics
reset arp detection statistics
[
interface
interface-type interface-number
]
Available in user view
ARP Detection Configuration Example I
Network requirements
As shown in
, configure Switch A as a DHCP server and enable DHCP snooping on Switch B.
Configure Host A as a DHCP client. Configure Host B whose IP address is 10.1.1.6 and MAC address
is 0001-0203-0607. Enable ARP detection for VLAN 10 to allow only packets from valid clients or hosts
to pass.
Summary of Contents for S5500-SI Series
Page 161: ...3 10 GigabitEthernet1 0 1 2 MANUAL...
Page 220: ...1 7 Clearing ARP entries from the ARP table may cause communication failures...
Page 331: ...1 7 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete...
Page 493: ...2 8...
Page 1111: ...1 10 Installing patches Installation completed and patches will continue to run after reboot...