Raisecom
ISCOM2600G-HI (A) Series Configuration Guide
10 Security
Raisecom Proprietary and Confidential
Copyright © Raisecom Technology Co., Ltd.
415
Other interfaces allow ARP packets complying with dynamic binding learnt by DHCP
Snooping to pass.
Configure rate limiting on ARP packets on downlink GE 1/1/2. The rate threshold is
configured to 20 pps and recovery time for rate limiting is configured to 15s.
Figure 10-3
Configuring dynamic ARP inspection
Configuration steps
Step 1
Configure GE 1/1/3 as the trusted interface.
Raisecom#config
Raisecom(config)#interface gigaethernet 1/1/3
Raisecom(config-gigaethernet1/1/3)#ip arp-inspection trust
Raisecom(config-gigaethernet1/1/3)#exit
Step 2
Configure static binding.
Raisecom(config)#ip arp-inspection static-config
Raisecom(config)#ip arp-inspection binding 10.10.10.1 gigaethernet 1/1/1
Step 3
Enable dynamic ARP inspection binding.
Raisecom(config)#ip dhcp snooping
Raisecom(config)#ip arp-inspection dhcp-snooping
Step 4
Configure rate limiting on ARP packets on the interface.