Chapter 17 Security Configuration
DAI Configuration Example
As shown in
Figure 40
, VLAN 2 is configured on switch and DAI is
run.
F
IGURE
40 DAI C
ONFIGURATION
E
XAMPLE
Prerequisites: DHCP SNOOPING function is opened in VLAN 2.
ZXR10(config)#ip dhcp snooping enable
ZXR10(config)#ip dhcp snooping vlan 2
VLAN 2 is configured on switch A and DAI is run.
ZXR10(config-vlan2)#ip arp inspection
Gei_1/1 and gei_1/2 are bound with VLAN 2.
Gei_1/1 is set as untrusted interface (the default attribute is un-
trusted interface).
The legal ARP packet(legal ARP packet: consistent witch IP+ port+
MAC in DHCP binding table) that host A sends to switch is broad-
cast in VLAN. Host B can receive ARP packet. The illegal packet is
discarded and not forwarded. Host B can’t receive ARP packet.
If gei_1/1 is set as trusted interface,
host A sends ARP packet(legal/illegal) to switch. Switch forwards
ARP packet by hardware to all interfaces that are bound with VLAN
1. Host B can receive ARP packet. When configuring interface lim-
Confidential and Proprietary Information of ZTE CORPORATION
179