ProSafe 7000 Managed Switch Software Administration Manual, Release 8.0.3
13-42
Security Management
v1.0, June 2010
Configuring Static Mapping
This script in this section shows how to configure static mapping.
CLI: Configuring Static Mapping
Create an ARP ACL.
(Netgear Switch) (Config)# arp access-list ArpFilter
Configure rule to allow the Static Client.
(Netgear Switch) (Config-arp-access-list)# permit ip host 192.168.10.2
mac host 00:11:85:ee:54:e9
Configure ARP ACL used for the VLAN 1.
(Netgear Switch) (Config)# ip arp inspection filter ArpFilter vlan 1
Now the ARP packets from the Static client will be through since it has an entry in the ARP ACL ARP
packets from the DHCP client is also through since it has DHCP snooping entry.
This command can have the optional static key word. If the static key word is given, packets that do not
match a permit statement are dropped without consulting the DHCP snooping bindings. That is in this
example, ARP packets from the DHCP client are dropped since it does not have a matching rule through it
has a DHCP snooping entry.
Web Interface: Configuring Static Mapping
1.
Create an ARP ACL.
a.
From the main menu, select Security > Control > Dynamic ARP Inspection > DAI ACL
Configuration.
b.
Enter the Name as
ArpFilter
.