38-16
Cisco 7600 Series Router Cisco IOS Software Configuration Guide, Release 12.2SX
OL-4266-08
Chapter 38 Configuring Dynamic ARP Inspection
DAI Configuration Samples
To clear or display DAI statistics, use the privileged EXEC commands in
Table 38-3
.
For the
show ip arp inspection statistics
command, the router increments the number of forwarded
packets for each ARP request and response packet on a trusted DAI port. The router increments the
number of ACL-permitted or DHCP-permitted packets for each packet that is denied by source MAC,
destination MAC, or IP validation checks, and the router increments the appropriate failure count.
To clear or display DAI logging information, use the privileged EXEC commands in
Table 38-4
:
DAI Configuration Samples
This section includes these samples:
•
Sample One: Two Switches Support DAI, page 38-16
•
Sample Two: One Switch Supports DAI, page 38-21
Sample One: Two Switches Support DAI
This procedure shows how to configure DAI when two routers support this feature. Host 1 is connected
to Router A, and Host 2 is connected to Router B as shown in
Figure 38-2 on page 38-4
. Both routers
are running DAI on VLAN 1 where the hosts are located. A DHCP server is connected to Router A. Both
hosts acquire their IP addresses from the same DHCP server. Router A has the bindings for Host 1 and
Host 2, and Router B has the binding for Host 2. Router A Fast Ethernet port 6/3 is connected to the
Router B Fast Ethernet port 3/3.
Note
•
DAI depends on the entries in the DHCP snooping binding database to verify IP-to-MAC address
bindings in incoming ARP requests and ARP responses. Make sure to enable DHCP snooping to
permit ARP packets that have dynamically assigned IP addresses. For configuration information, see
Chapter 37, “Configuring DHCP Snooping.”
•
This configuration does not work if the DHCP server is moved from Router A to a different location.
Table 38-3 Commands for Clearing or Displaying DAI Statistics
Command
Description
clear ip arp inspection statistics
Clears DAI statistics.
show ip arp inspection statistics
[
vlan
vlan_range
]
Displays statistics for forwarded, dropped, MAC
validation failure, IP validation failure, ACL
permitted and denied, and DHCP permitted and
denied packets for the specified VLAN. If no
VLANs are specified or if a range is specified,
displays information only for VLANs with DAI
enabled (active).
Table 38-4 Commands for Clearing or Displaying DAI Logging Information
Command
Description
clear ip arp inspection log
Clears the DAI log buffer.
show ip arp inspection log
Displays the configuration and contents of the DAI log buffer.