Configuring Security
Dynamic ARP Inspection
Cisco 500 Series Stackable Managed Switch Administration Guide
346
18
STEP 2
Click Apply. The settings are defined, and the Running Configuration file is
updated.
Defining Dynamic ARP Inspection Interfaces Settings
Packets from untrusted ports/LAGs are checked against the ARP Access Rules
table and the DHCP Snooping Binding database if DHCP Snooping is enabled (see
the
DHCP Snooping Binding Database
page).
By default, ports/LAGs are ARP Inspection untrusted.
To change the ARP trusted status of a port/LAG:
STEP 1
Click Security > ARP Inspection > Interface Settings. The
Interface Settings page
is displayed
.
The ports/LAGs and their ARP trusted/untrusted status are displayed.
STEP 2
To set a port/LAG as untrusted, select the port/LAG and click
Edit
. The
Edit
Interface Settings
page is displayed.
STEP 3
Select Trusted or Untrusted and click
Apply
to save the settings to the Running
Configuration file.
Defining ARP Inspection Access Control
To add entries to the ARP Inspection table:
STEP 1
Click Security > ARP Inspection > ARP Access Control. The
ARP Access Control
page is displayed.
STEP 2
To add an entry, click
Add
. The
Add ARP Access Control
page is displayed.
STEP 3
Enter the fields:
•
ARP Access Control Name
—Enter a user-created name.
•
MAC Address—MAC address of packet.
•
IP Address—IP address of packet.