Layer 3 Forward and ARP Configuration
Chapter 6 Dynamic ARP Inspection Configuration
http://www.level1.com
6-2
configures the untrusted port.
3. Configure the rate for the untrusted ARP packet
Command
Explanation
Port Mode
ip arp inspection limit-rate <rate>
no ip arp inspection limit-rate <rate>
Limit the ARP packet rate of the untrusted
port. The no command cancels the limited
cpu rate.
6.3 Dynamic ARP Inspection Configuration Example
PC
DHCP Server
Other Server
Environment: DHCP server and PC client are both en vlan 10.
The MAC of the DHCP server is 00-24-8c-01-05-90, the IP address of 192.168.10.2
needs to be distributed statically, the DHCP server is connected to e 1/0/1. The MAC of
the specific server (Other Server) is 00-24-8c-01-05-80, the IP address of 192.168.10.3
needs to be distributed statically, the other server is connected to e 1/0/2. The MAC of the
PC client is 00-24-8c-01-05-96, the IP address is gotten dynamically through the DHCP.
The PC is connected to e 1/0/3. The layer3 interface of vlan 10 is 192.168.10.1, the MAC
is 00-03-0F-01-02-03.
The configuration is as below:
ip arp inspection vlan 10
ip dhcp snooping enable
ip dhcp snooping vlan 10
!
Interface Ethernet1/0/1
description connect DHCP Server
switchport access vlan 10
ip dhcp snooping trust