171
VLAN State
Enter the VLAN IDs you want the Switch to enable ARP Inspection for.
You can designate multiple VLANs individually by using a comma (,)
and by range with a hyphen (-).
Trusted Ports
Select the ports which are trusted and deselect the ports which are
untrusted.
The Switch does not discard ARP packets on trusted ports for any
reason.
The Switch discards ARP packets on untrusted ports in the following
situations:
• The sender’s information in the ARP packet does not match any of the
current bindings.
• The rate at which ARP packets arrive is too high. You can specify the
maximum rate at which ARP packets can arrive on untrusted ports.
Select All
Click this to set all ports to trusted.
Deselect All
Click this to set all ports to untrusted.
Apply
Click
Apply
to add/modify the settings.
Refresh
Click
Refresh
to begin configuring this screen afresh.
ARP
Inspection
Status
ARP
Inspection
State
This field displays the current status of the ARP Inspection feature,
Enabled
or
Disabled
.
Enabled on VLAN
This field displays the VLAN IDs that have ARP Inspection enabled on
them. This will display
None
if no VLANs have been set.
Trusted Ports
This field displays the ports which are trusted. This will display
None
if no ports are trusted.
7.1.3.2.
Filter Table
7.1.3.2.1.
Introduction
Dynamic ARP inspections validates the packet by performing IP to MAC address binding
inspection stored in a trusted database (the DHCP snooping database) before forwarding the
packet. When the Switch identifies an unauthorized ARP packet, it automatically creates a MAC
address filter to block traffic from the source MAC address and source VLAN ID of the
unauthorized ARP packet. The switch also periodically deletes entries if the age-time for the
entry is expired.
If the ARP Inspection is enabled and the system detects invalid hosts, the system will create
a filtered entry in the MAC address table.
When Port link down and ARP Inspection was disabled, Switch will remove the MAC-filter
entries learned by this port.
When Port link down and ARP Inspection was enabled, Switch will remove the MAC-filter
entries learned by this port.
The maximum entry of the MAC address filter table is 256.