Enabling trust on a port
The default trust setting for a port is untrusted. For ports that are connected to host ports, leave their trust settings as untrusted. If the
port is part of a LAG, enable ARP inspection trust on the primary port of the LAG.
To enable trust on a port, enter commands such as the following.
device(config)# interface ethernet 1/1/4
device(config-if-e10000-1/1/4)# arp inspection trust
The commands change the CLI to the interface configuration level of port 1/1/4 and set the trust setting of port 1/1/4 to trusted.
Syntax:
[no] arp
inspection
trust
Disabling or re-enabling syslog messages for DAI
You can disable or re-enable syslog messages for Dynamic ARP Inspection. Syslog messages are enabled by default on the device.
1. Enter global configuration mode.
2. Enter the
ip arp inspection syslog disable
command to disable syslog messages. Use the
no
form of the command to re-
enable syslog messages for DAI.
The following example shows disabling the syslog messages for DAI.
device(config)# ip arp inspection syslog disable
Multi-VRF support for DAI
DAI supports Multi-VRF (Virtual Routing and Forwarding) instances. You can deploy multiple VRFs on a Brocade Ethernet switch. Each
VLAN having a Virtual Ethernet (VE) interface is assigned to a VRF.
You can enable DAI on individual VLANs and assign any interface as the ARP inspection trust interface. If an interface is a tagged port in
this VLAN, you can turn on the trust port per VRF, so that traffic intended for other VRF VLANs will not be trusted.
To configure DAI to support a VRF instance, do the following:
•
Enable the
acl-per-port-per-vlan
setting. DAI requires that the
acl-per-port-per-vlan
setting be enabled.
Brocade(config)# enable acl-per-port-per-vlan
Reload required. Please write memory and then reload or power cycle.
•
Configure DAI on a VLAN using the
ip arp inspection vlan
vlan-id
command.
Brocade(config)# ip arp inspection vlan 2
Syntax:
ip arp
inspection
vlan
vlan-id
•
To add a static ARP inspection entry for a specific VRF, use the arp
ip-address mac-address
inspection command in the VRF
CLI context.
Brocade(config-vrf-one-ipv4)# arp 5.5.5.5 00a2.bbaa.0033 inspection
Syntax:
arp
ip-address
mac-address
inspection
Enabling trust on a port for a specific VRF
The default trust setting for a port is untrusted. For ports that are connected to host ports, leave their trust settings as untrusted.
Dynamic ARP inspection
Brocade FastIron Layer 3 Routing Configuration Guide
34
53-1003903-04
Содержание ICX 7250 series
Страница 2: ...Brocade FastIron Layer 3 Routing Configuration Guide 2 53 1003903 04...
Страница 16: ...Brocade FastIron Layer 3 Routing Configuration Guide 16 53 1003903 04...
Страница 20: ...Brocade FastIron Layer 3 Routing Configuration Guide 20 53 1003903 04...
Страница 36: ...Brocade FastIron Layer 3 Routing Configuration Guide 36 53 1003903 04...
Страница 124: ...Brocade FastIron Layer 3 Routing Configuration Guide 124 53 1003903 04...
Страница 174: ...Brocade FastIron Layer 3 Routing Configuration Guide 174 53 1003903 04...
Страница 188: ...Brocade FastIron Layer 3 Routing Configuration Guide 188 53 1003903 04...
Страница 202: ...Brocade FastIron Layer 3 Routing Configuration Guide 202 53 1003903 04...
Страница 470: ...Brocade FastIron Layer 3 Routing Configuration Guide 470 53 1003903 04...