Monitoring Dai - Cisco Catalyst 2960-XR Security Configuration Manual

Ios release 15.0 2 ex1
Hide thumbs Also See for Catalyst 2960-XR:
Table of Contents

Advertisement

Monitoring DAI

Command or Action
Step 3
exit
Step 4
show ip arp inspection vlan
vlan-range
Step 5
copy running-config
startup-config
Monitoring DAI
To monitor DAI, use the following commands:
Command
clear ip arp inspection statistics
show ip arp inspection statistics [vlan vlan-range]
clear ip arp inspection log
show ip arp inspection log
For the show ip arp inspection statistics command, the switch increments the number of forwarded packets
for each ARP request and response packet on a trusted dynamic ARP inspection port. The switch increments
the number of ACL or DHCP permitted packets for each packet that is denied by source MAC, destination
MAC, or IP validation checks, and the switch increments the appropriate.
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
210
Purpose
• For ip, check the ARP body for invalid and unexpected IP addresses. Addresses
include 0.0.0.0, 255.255.255.255, and all IP multicast addresses. Sender IP
addresses are checked in all ARP requests and responses, and target IP addresses
are checked only in ARP responses.
You must specify at least one of the keywords. Each command overrides the configuration
of the previous command; that is, if a command enables src and dst mac validations,
and a second command enables IP validation only, the src and dst mac validations are
disabled as a result of the second command.
Return to privileged EXEC mode.
Verify your settings.
(Optional) Save your entries in the configuration file.
Configuring Dynamic ARP Inspection
Description
Clears dynamic ARP inspection statistics.
Displays statistics for forwarded, dropped, MAC
validation failure, IP validation failure, ACL permitted
and denied, and DHCP permitted and denied packets
for the specified VLAN. If no VLANs are specified
or if a range is specified, displays information only
for VLANs with dynamic ARP inspection enabled
(active).
Clears the dynamic ARP inspection log buffer.
Displays the configuration and contents of the
dynamic ARP inspection log buffer.
OL-29434-01

Advertisement

Table of Contents
loading

Table of Contents