Configuring Device Security
Defining Dynamic ARP Inspection
ESW 500 Series Switches Administration Guide
199
5
Assigning ARP Inspection VLAN Settings
The
ARP Inspection VLAN Settings Page
contains fields for enabling ARP
Inspection on VLANs. In the Enabled VLAN table, users assign static ARP
Inspection Lists to enabled VLANs. When a packet passes through an untrusted
interface which is enabled for ARP Inspection, the device performs the following
checks in order:
•
Determines if the packet’s IP address and MAC address exist in the static ARP
Inspection list. If the addresses match, the packet passes through the interface.
•
If the device does not find a matching IP address, but DHCP Snooping is
enabled on the VLAN, the device checks the DHCP Snooping database for the
IP address-VLAN match. If the entry exists in the DHCP Snooping database, the
packet passes through the interface.
•
If the packet’s IP address is not listed in the ARP Inspection List or the DHCP
Snooping database, the device rejects the packet.
NOTE
To define ARP Inspection on VLANs, ARP Inspection List(s) must be defined before
continuing.
In the following example, the List Name field is empty on the Add VLAN Settings
page. If you add a list in the steps above, then the list will be populated with all the
entries.
To define ARP Inspection on VLANs: