ZXR10 5900/5200 Series User Manual (Basic Configuration Volume)
DAI detects ARP packet according to the binding relationship be-
tween IP and MAC address which is stored in trust database. When
DHCP SNOOPING of VLAN is open, database is created by DHCP
SNOOPING. If ARP packet is received from a trust port, switch need
not any detection and forwards packet directly. If ARP packet is
received from a untrust port, switch only forwards valid packet.
Configuring DAI
Step Command
Function
1
Zxr10(config-gei_1/x)#
ip arp inspection trust
This configures trust attribute
of interface.
2
Zxr10 (config-smartgroupX)#
ip arp inspection trust
This configures trust attribute
of Smartgroup interface.
3
Zxr10(config)#
ip arp inspection validate
{[
des-mac
][
ip
][
src-mac
]}
This configures global ARP
validate inspection function.
4
Zxr10 (config-gei_1/x)#
ip arp inspection limit
<
1-100
>
This configures the limited
speed of interface.
As for untrusted interface, the
default is 15pps.
As for trusted interface, ARP
packet speed is not limited.
5
Zxr10(config-vlanX)#
ip arp inspection
This configures DAI enabled
of VLAN.
DAI Maintenance and Diagnosis
ZXR10 5900/5200 provides
show
command to help maintenance
and diagnosis. Common commands used in DAI maintenance and
diagnosis are as follows.
1. To view trusted attribute of interface, use the following com-
mand.
show ip arp inspection
{
interface interface_name
}
2. To view ARP packet validated inspection information, use the
following command.
show ip arp inspection configure
3. To view DAI configuration information of VLAN, use the follow-
ing command.
show ip arp inspection vlan
[{<
1-4094
>|
disable
|
enable
|
name vlan_name
}]
178
Confidential and Proprietary Information of ZTE CORPORATION