Assigning Arp Inspection Vlan Settings - Cisco SGE2000 - - Gigabit Switch Administration Manual

48-port 10/100/1000 sfe/sge managed switches
Hide thumbs Also See for SGE2000 - Cisco - Gigabit Switch:
Table of Contents

Advertisement

Configuring Device Security
Defining Dynamic ARP Inspection
STEP 3
STEP 4
Cisco Small Business SFE/SGE Managed Switches Administration Guide
Add ARP List Page
In addition to the fields in the ARP Inspection List Page, the Add ARP List Page
contains the additional field:
List Name — Specifies a name for the new ARP list.
Define the fields.
Click Apply. The new ARP Inspection List is added, and the device is updated.

Assigning ARP Inspection VLAN Settings

ARP Inspection VLAN Settings Page
The
Inspection on VLANs. In the Enabled VLAN table, users assign static ARP
Inspection Lists to enabled VLANs. When a packet passes through an untrusted
interface which is enabled for ARP Inspection, the device performs the following
checks in order:
Determines if the packet's IP address and MAC address exist in the static ARP
Inspection list. If the addresses match, the packet passes through the interface.
If the device does not find a matching IP address, but DHCP Snooping is
enabled on the VLAN, the device checks the DHCP Snooping database for the
IP address-VLAN match. If the entry exists in the DHCP Snooping database, the
packet passes through the interface.
If the packet's IP address is not listed in the ARP Inspection List or the DHCP
Snooping database, the device rejects the packet.
To define ARP Inspection on VLANs:
contains fields for enabling ARP
4
148

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sge2000pSge2010Sfe2010Sfe2000

Table of Contents