169
Dynamic ARP inspection ensures that only valid ARP requests and responses are relayed. The
switch performs these activities:
Intercepts all ARP requests and responses on untrusted ports.
Verifies that each of these intercepted packets has a valid IP-to-MAC address binding before
it updates the local ARP cache or before it forwards the packet to the appropriate destination.
Trusted and untrusted port
This setting is independent of the trusted and untrusted setting of the DHCP Snooping.
The Switch does not discard ARP packets on trusted ports for any reasons.
The Switch discards ARP packets on un-trusted ports if the sender’s information in the
ARP packets does not match any of the current bindings.
Normally, the trusted ports are the uplink port and the untrusted ports are connected to
subscribers.
Configurations:
Users can enable/disable the ARP Inspection on the Switch. Users also can enable/disable the
ARP Inspection on a specific VLAN. If the ARP Inspection on the Switch is disabled, the ARP
Inspection is disabled on all VLANs even some of the VLAN ARP Inspection are enabled.
Default Settings
The ARP Inspection on the Switch is disabled.
The age time for the MAC filter is 5 minutes.
ARP Inspection is enabled in VLAN(s): None.
Port Trusted
Port Trusted
----
------- ----
-------
1 no 2 no
3 no 4 no
5 no 6 no
7 no 8 no
9 no 10
no
11 no 12
no
Notices
There are a global state and per VLAN states.
✓
When the global state is disabled, the ARP Inspection on the Switch is disabled even per
VLAN states are enabled.
✓
When the global state is enabled, user must enable per VLAN states to enable the ARP
Inspection on the specific VLAN.
7.1.3.1.2.
CLI Configuration
Node
Command
Description
enable
show arp-inspection
This command displays the current ARP Inspection