426
To do…
Command…
Remarks
2.
Enter VLAN view.
vlan
vlan-id
—
3.
Enable ARP restricted
forwarding.
arp restricted-forwarding enable
Required
Disabled by default
Displaying and maintaining ARP detection
To do…
Command…
Remarks
Display the VLANs enabled
with ARP detection
display arp detection
[
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display the ARP detection
statistics
display arp detection statistics
[
interface
interface-type interface-number
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Clear the ARP detection
statistics
reset arp detection statistics
[
interface
interface-
type interface-number
]
Available in user view
ARP detection with DHCP snooping configuration example
Network requirements
As shown in
, configure Router A as a DHCP server, and enable DHCP snooping on Router
B. Configure Host A as a DHCP client. Configure Host B whose IP address is 10.1.1.6 and MAC
address is 0001-0203-0607. Enable ARP detection for VLAN 10 to allow only packets from valid clients
or hosts to pass.
Figure 147
Network diagram for ARP detection configuration
Router A
Router B
Host A
Host B
GE1/0/3
Vlan-int10
10.1.1.1/24
Gateway
DHCP server
GE1/0/1
GE1/0/3
GE1/0/2
VLAN 10