ProSafe 7000 Managed Switch Software Administration Manual, Release 8.0.3
Security Management
13-41
v1.0, June 2010
d.
Click
Apply
. At the end of this configuration a screen similar to the following displays.
Figure
13-46
Now all the ARP packets received on the ports that are member of VLAN are copied to CPU for ARP
inspection. If there are trusted ports, it can configured as trusted port as in the next step. ARP packets
received on the trusted ports are not copied to the CPU.
Note
: Make sure the Administrator PC has a DHCP snooping entry or accessing the device through the
trusted port for ARP. Otherwise you may get disconnected from the device.
6.
Configure a port 1/0/1 as trusted.
a.
From the main menu, select Security > Control > Dynamic ARP Inspection > DAI Interface
Configuration.
b.
Select the checkbox for Interface
1/0/1
.
c.
Set the Trust Mode as
Enable
.
d.
Click
Apply
. A screen similar to the following displays.
Figure
13-47
Now ARP packets from the DHCP client will be through since it has DHCP snooping entry, however ARP
packets from the static client is dropped, since it does have a DHCP snooping entry. It can be over come by
static configuration as described in
“Configuring Static Mapping” on page
13-42
.