
Security Measures
169
Instruction Manual - NXA-ENET8-POE+
Perform these steps to configure VLAN settings for ARP Inspection:
1.
Click
Security
>
ARP Inspection
.
2.
Select
Configure VLAN
from the Step list.
3.
Enable ARP inspection for the required VLANs, select an ARP ACL filter to check for configured addresses, and select the Static
option to bypass checking the DHCP snooping bindings database if required.
4.
Click
Apply
.
Configuring Interface Settings for ARP Inspection
Use the Security > ARP Inspection (Configure Interface) page to specify the ports that require ARP inspection, and to adjust the
packet inspection rate.
The following table lists the options on this page:
Perform these steps to configure interface settings for ARP Inspection:
1.
Click
Security
>
ARP Inspection
.
2.
Select
Configure Interface
from the Step list.
3.
Specify any untrusted ports which require ARP inspection, and adjust the packet inspection rate.
4.
Click
Apply
.
FIG. 197
Configuring VLAN Settings for ARP Inspection
Security - ARP Inspection Options
Interface
Port or trunk identifier
Trust Status
Configures the port as trusted or untrusted. (Default: Untrusted)
By default, all untrusted ports are subject to ARP packet rate limiting, and all trusted ports are
exempt from ARP packet rate limiting.
Packets arriving on trusted interfaces bypass all ARP Inspection and ARP Inspection Validation
checks and will always be forwarded, while those arriving on untrusted interfaces are subject to all
configured ARP inspection tests.
Packet Rate Limit
Sets the maximum number of ARP packets that can be processed by CPU per second on trusted or
untrusted ports. (Range: 0-2048; Default: 15)
Setting the rate limit to 0 means that there is no restriction on the number of ARP packets that can
be processed by the CPU.
The switch will drop all ARP packets received on a port which exceeds the configured
ARP-packets-per-second rate limit.
FIG. 198
Configuring Interface Settings for ARP Inspection