Transition Networks
S4224 Web User Guide
33558 Rev. C
Page 129 of 669
ARP Inspection Configuration
ARP Inspection is a security feature. Several types of attacks can be launched against a host or devices
connected to Layer 2 networks by "poisoning" the ARP caches. The ARP Inspection feature is used to
block such attacks. Only valid ARP requests and responses can go through the switch device.
Port
Configuration
The
Configuration
>
Security
>
Network
>
ARP
Inspection
>
Port
Configuration
menu path provides
global ARP Inspection configuration and Port level ARP Inspection configuration.
The ARP Inspection parameters are explained below.
ARP Inspection Configuration Mode
Enable or disable the Global ARP Inspection feature.
Port Mode Configuration
Specify ARP Inspection is enabled on which ports. Only when both Global Mode and Port Mode
on a given port are enabled, ARP Inspection is enabled on this given port. Possible modes are:
Enabled
: Enable ARP Inspection operation.
Disabled
: Disable ARP Inspection operation.
To inspect the VLAN configuration, enable the "
Check VLAN
" setting. The default setting of
"Check VLAN" is disabled. Possible "Check VLAN" settings are:
Enabled
: Enable check VLAN operation. When "Check VLAN" is enabled, the log type of ARP
Inspection will refer to the VLAN setting.
Disabled
: Disable check VLAN operation. When "Check VLAN" is disabled, the log type of ARP
Inspection will refer to the port setting.
If only the Global Mode and Port Mode on a given port are enabled, and the setting of "Check
VLAN" is disabled, the log type of ARP Inspection will refer to the port setting. The log types are:
None
: Log nothing.
Deny
: Log denied entries.