Cisco 4500M Software Manual page 478

Software guide
Table of Contents

Advertisement

Configuring Dynamic ARP Inspection
Configure interface fa6/3 as trusted:
Step 3
S1# conf t
Enter configuration commands, one per line.
S1(config)# in fa6/3
S1(config-if)# ip arp inspection trust
S1(config-if)# end
S1# show ip arp inspection interfaces fastEthernet 6/3
Interface
---------------
Fa6/3
S1#
Verify the bindings:
Step 4
S1# show ip dhcp snooping binding
MacAddress
------------------
00:02:00:02:00:02
S1#
Check the statistics before and after Dynamic ARP processes any packets:
Step 5
S1# show ip arp inspection statistics vlan 1
Vlan
----
1
Vlan
----
1
Vlan
----
1
S1#
If H1 then sends out two ARP requests with an IP address of 1.1.1.2 and a MAC address of
0002.0002.0002, both requests are permitted, as reflected in the following statistics:
S1# show ip arp inspection statistics vlan 1
Vlan
----
1
Vlan
----
1
Vlan
----
1
S1#
If H1 then tries to send an ARP request with an IP address of 1.1.1.3, the packet is dropped and an error
message is logged:
00:12:08: %SW_DAI-4-DHCP_SNOOPING_DENY: 2 Invalid ARPs (Req) on Fa6/4, vlan
1.([0002.0002.0002/1.1.1.3/0000.0000.0000/0.0.0.0/02:42:35 UTC Tue Jul 10 2001])
S1# show ip arp inspection statistics vlan 1
S1#
Software Configuration Guide—Release 12.2(25)EW
34-6
Trust State
-----------
Trusted
IpAddress
---------------
1.1.1.2
Forwarded
Dropped
---------
-------
0
DHCP Permits
ACL Permits
------------
-----------
0
Dest MAC Failures
IP Validation Failures
-----------------
----------------------
0
Forwarded
Dropped
---------
-------
2
DHCP Permits
ACL Permits
------------
-----------
2
Dest MAC Failures
IP Validation Failures
-----------------
----------------------
0
Chapter 34
Understanding and Configuring Dynamic ARP Inspection
End with CNTL/Z.
Rate (pps)
----------
None
Lease(sec)
Type
----------
-------------
4993
dhcp-snooping
DHCP Drops
ACL Drops
----------
----------
0
0
Source MAC Failures
-------------------
0
0
0
DHCP Drops
ACL Drops
----------
----------
0
0
Source MAC Failures
-------------------
0
0
0
VLAN
Interface
----
--------------------
1
FastEthernet6/4
0
0
OL-6696-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

4500 series

Table of Contents