![Brocade Communications Systems ICX 7250 series Скачать руководство пользователя страница 32](http://html1.mh-extra.com/html/brocade-communications-systems/icx-7250-series/icx-7250-series_configuration-manual_2817203032.webp)
address and source MAC address against the ARP table. For an ARP reply packet, DAI checks the source IP, source MAC, destination IP,
and destination MAC addresses. DAI forwards the valid packets and discards those with invalid IP-to-MAC address bindings.
When ARP packets reach a trusted port, DAI lets them through, as shown in the following figure.
FIGURE 2
Dynamic ARP inspection at work
ARP and DHCP snoop entries
DAI uses the IP-to-MAC mappings in the ARP table to validate ARP packets received on untrusted ports. DAI relies on the following
entries:
•
Dynamic ARP - Normal ARP learned from trusted ports.
•
Static ARP - Statically configured IP/MAC/port mapping.
•
Inspection ARP - Statically configured IP-to-MAC mapping, where the port is initially unspecified. The actual physical port
mapping will be resolved and updated from validated ARP packets. Refer to
Configuring an inspection ARP entry
•
DHCP-Snooping ARP - Information collected from snooping DHCP packets when DHCP snooping is enabled on VLANs.
DHCP snooping entries are stored in a different table and are not part of the ARP table.
The status of an ARP entry is either pending or valid:
•
Valid - The mapping is valid, and the port is resolved. This is always the case for static ARP entries.
•
Pending - For normal dynamic ARP entries before they are resolved, and the port is mapped. Their status changes to valid
when they are resolved, and the port is mapped.
Refer to System reboot and the binding database section in the
Brocade FastIron DHCP Configuration Guide
.
Configuration notes and feature limitations for DAI
The following configuration notes and limitations apply when configuring DAI:
•
To run Dynamic ARP Inspection, you must first enable support for ACL filtering based on VLAN membership or VE port
membership. To do so, enter the following commands at the global configuration level of the CLI.
device(config)# enable ACL-per-port-per-vlan
device(config)# write memory
device(config)# exit
device# reload
Dynamic ARP inspection
Brocade FastIron Layer 3 Routing Configuration Guide
32
53-1003903-04
Содержание ICX 7250 series
Страница 2: ...Brocade FastIron Layer 3 Routing Configuration Guide 2 53 1003903 04...
Страница 16: ...Brocade FastIron Layer 3 Routing Configuration Guide 16 53 1003903 04...
Страница 20: ...Brocade FastIron Layer 3 Routing Configuration Guide 20 53 1003903 04...
Страница 36: ...Brocade FastIron Layer 3 Routing Configuration Guide 36 53 1003903 04...
Страница 124: ...Brocade FastIron Layer 3 Routing Configuration Guide 124 53 1003903 04...
Страница 174: ...Brocade FastIron Layer 3 Routing Configuration Guide 174 53 1003903 04...
Страница 188: ...Brocade FastIron Layer 3 Routing Configuration Guide 188 53 1003903 04...
Страница 202: ...Brocade FastIron Layer 3 Routing Configuration Guide 202 53 1003903 04...
Страница 470: ...Brocade FastIron Layer 3 Routing Configuration Guide 470 53 1003903 04...