EKI-9500 Series User Manual
172
4.4.5.3
Interface
Use the Interface Configuration page to configure the per-interface Dynamic ARP
Inspection (DAI) settings.
To access this page, click
Switching
>
Dynamic ARP Inspection
>
Interface
.
Figure 4.184 Switching > Dynamic ARP Inspection > Interface
The following table describes the items in the previous figure.
Log Invalid Packets
Indicates whether DAI logging is enabled on this VLAN. When logging
is enabled, DAI generates a log message whenever an invalid ARP
packet is discovered and dropped.
ARP ACL Name
The name of the of ARP access control list (ACL) that the VLAN uses
as the filter for ARP packet validation. The ARP ACL must already
exist on the system to associate it with a DAI-enabled VLAN. ARP
ACLs include permit rules only.
Static
Determines whether to use the DHCP snooping database for ARP
packet validation if the packet does not match any ARP ACL rules. The
options are as follows:
Enable: The ARP packet will be validated by the ARP ACL rules
only. Packets that do not match any ARP ACL rules are dropped
without consulting the DHCP snooping database.
Disable: The ARP packet needs further validation by using the
entries in the DHCP Snooping database.
Submit
Click
Submit
to save the values.
Cancel
Click
Cancel
to close the window.
Item
Description
Item
Description
Interface
The interface associated with the rest of the data in the row. In the Edit
Interface Configuration window, this field identifies the interface that is
being configured.
Trust State
Indicates whether the DAI feature should check traffic on the interface
for possible ARP packet violations. Trust state can be enabled or dis-
abled after you select an interface and click
Edit
. This field has one of
the following values:
Enabled: The interface is trusted. ARP packets arriving on this
interface are forwarded without DAI validation.
Disabled: The interface is not trusted. ARP packets arriving on
this interface are subjected to ARP inspection.
Rate Limit
The maximum rate for incoming ARP packets on the interface, in pack-
ets per second (pps). If the incoming rate exceeds the configured limit,
the ARP packets are dropped. Rate limiting can be enabled or disabled
after you select an interface and click
Edit
.
Содержание EKI-9512-C0IDW10E
Страница 1: ...User Manual EKI 9500 Series Full Managed Ethernet Switches...
Страница 20: ...Chapter 1 1Product Overview...
Страница 28: ...Chapter 2 2Switch Installation...
Страница 38: ...Chapter 3 3Configuration Utility...
Страница 43: ...Chapter 4 4Managing Switch...