168
Binding Table
Bindings are used by DHCP snooping and ARP inspection to distinguish between authorized and
unauthorized packets in the network. The Switch learns the dynamic bindings by snooping DHCP
packets and from information provided manually in the
Static Entry Settings
screen.
Parameter
Description
MAC Address
This field displays the source MAC address in the binding.
IP Address
This field displays the IP address assigned to the MAC address in the
binding.
Lease
This field displays how long the binding is valid.
VLAN
This field displays the source VLAN ID in the binding.
Port
This field displays the port number in the binding. If this field is blank, the
binding applies to all ports.
Type
This field displays how the Switch learned the binding.
Static
: This binding was learned from information provided manually by
an administrator.
Dynamic
: This binding was learned by snooping DHCP packets.
7.1.3.
ARP Inspection
7.1.3.1.
ARP Inspection
7.1.3.1.1.
Introduction
Dynamic ARP inspection is a security feature which validates ARP packet in a network by
performing IP to MAC address binding inspection. Those will be stored in a trusted database (the
DHCP snooping database) before forwarding. Dynamic ARP intercepts, logs, and discards ARP
packets with invalid IP-to-MAC address bindings. This capability protects the network from
certain man-in-the-middle attacks.