Chapter 75 ARP Inspection
XGS2220 Series User’s Guide
503
Figure 369
SECURITY > IPv4 Source Guard > ARP Inspection > ARP Insp. Setup
The following table describes the labels in this screen.
Table 289 SECURITY > IPv4 Source Guard > ARP Inspection > ARP Insp. Setup
LABEL
DESCRIPTION
ARP Inspection Setup
Active
Enable the switch button to enable ARP inspection on the Switch. You still have to enable
ARP inspection on specific VLAN and specify trusted ports.
Filter Aging Time
Filter Aging Time
This setting has no effect on existing MAC address filters.
Enter how long (1 – 2147483647 seconds) the MAC address filter remains in the Switch after
the Switch identifies an unauthorized ARP packet. The Switch automatically deletes the
MAC address filter afterwards. Type 0 if you want the MAC address filter to be permanent.
Log Profile
Log Buffer Size
Enter the maximum number (1 – 1024) of log messages that were generated by ARP packets
and have not been sent to the syslog server yet. Make sure this number is appropriate for
the specified
Syslog Rate
and
Log Interval
.
If the number of log messages in the Switch exceeds this number, the Switch stops recording
log messages and simply starts counting the number of entries that were dropped due to
unavailable buffer. Click
Clearing Log Status Table
in the
SECURITY
>
IPv4 Source Guard
>
ARP Inspection
>
ARP Insp. Log Status
screen to clear the log and reset this counter.
Syslog Rate
Type the maximum number of syslog messages the Switch can send to the syslog server in
one batch. This number is expressed as a rate because the batch frequency is determined
by the
Log Interval
. You must configure the syslog server to use this. Enter 0 if you do not
want the Switch to send log messages generated by ARP packets to the syslog server.
The relationship between
Syslog Rate
and
Log Interval
is illustrated in the following
examples:
• Four invalid ARP packets per second,
Syslog Rate
is 5,
Log Interval
is 1: the Switch sends 4
syslog messages every second.
• Six invalid ARP packets per second,
Syslog Rate
is 5,
Log Interval
is 2: the Switch sends 5
syslog messages every 2 seconds.