Chapter 24: General Security Measures
ARP Inspection
– 878 –
any of the ACL rules are dropped. Address bindings in the DHCP
snooping database are not checked.
•
If static mode is not enabled, packets are first validated against the
specified ARP ACL. Packets matching a deny rule are dropped. All
remaining packets are validated against the address bindings in the
DHCP snooping database.
E
XAMPLE
Console(config)#ip arp inspection filter sales vlan 1
Console(config)#
ip arp inspection
log-buffer logs
This command sets the maximum number of entries saved in a log
message, and the rate at which these messages are sent. Use the
no
form
to restore the default settings.
S
YNTAX
ip arp inspection log-buffer logs
message-number
interval
seconds
no ip arp inspection log-buffer logs
message-number
- The maximum number of entries saved in a log
message. (Range: 0-256, where 0 means no events are saved and
no messages sent)
seconds
- The interval at which log messages are sent.
(Range: 0-86400)
D
EFAULT
S
ETTING
Message Number: 5
Interval: 1 second
C
OMMAND
M
ODE
Global Configuration
C
OMMAND
U
SAGE
•
ARP Inspection must be enabled with the
command
before this command will be accepted by the switch.
•
By default, logging is active for ARP Inspection, and cannot be disabled.
•
When the switch drops a packet, it places an entry in the log buffer.
Each entry contains flow information, such as the receiving VLAN, the
port number, the source and destination IP addresses, and the source
and destination MAC addresses.
•
If multiple, identical invalid ARP packets are received consecutively on
the same VLAN, then the logging facility will only generate one entry in
the log buffer and one corresponding system message.
•
The maximum number of entries that can be stored in the log buffer is
determined by the
message-number
parameter. If the log buffer fills up
Содержание SSE-G2252
Страница 42: ...44 General IP Routing on page 627...
Страница 174: ...Chapter 6 VLAN Configuration Configuring VLAN Mirroring 178 Figure 6 27 Showing the VLANs to Mirror...
Страница 511: ...Chapter 14 Basic Administration Protocols UDLD Configuration 518 Figure 14 100 Displaying UDLD Neighbor Information...
Страница 603: ...Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 609...
Страница 883: ...Chapter 24 General Security Measures Port based Traffic Segmentation 894...
Страница 989: ...Chapter 30 Congestion Control Commands Automatic Traffic Control Commands 1000 Console...
Страница 1007: ...Chapter 33 Address Table Commands 1019...
Страница 1137: ...Chapter 38 Quality of Service Commands 1150...
Страница 1366: ...Chapter 46 IP Routing Commands Global Routing Configuration 1381 Connected 2 Total 2 FIB 0 Console...