Configuring Dynamic Arp Inspection In Dhcp Environments - Cisco Catalyst 2960-X Security Configuration Manual

Cisco ios release 15.0(2)ex
Hide thumbs Also See for Catalyst 2960-X:
Table of Contents

Advertisement

Configuring Dynamic ARP Inspection in DHCP Environments

Command or Action
Step 11
show running-config
Example:
Switch# show running-config
Step 12
copy running-config startup-config
Example:
Switch# copy running-config
startup-config
Configuring Dynamic ARP Inspection in DHCP Environments
Before You Begin
This procedure shows how to configure dynamic ARP inspection when two switches support this feature.
Host 1 is connected to Switch A, and Host 2 is connected to Switch B. Both switches are running dynamic
ARP inspection on VLAN 1 where the hosts are located. A DHCP server is connected to Switch A. Both hosts
acquire their IP addresses from the same DHCP server. Therefore, Switch A has the bindings for Host 1 and
Host 2, and Switch B has the binding for Host 2.
Note
Dynamic ARP inspection depends on the entries in the DHCP snooping binding database to verify
IP-to-MAC address bindings in incoming ARP requests and ARP responses. Make sure to enable DHCP
snooping to permit ARP packets that have dynamically assigned IP addresses.
Follow these steps to configure dynamic ARP inspection. You must perform this procedure on both switches.
This procedure is required.
Catalyst 2960-X Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX
252
Purpose
Verifies your entries.
(Optional) Saves your entries in the configuration file.
Configuring Dynamic ARP Inspection
OL-29048-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents