Arp Inspection; Cli Configurations - Tripp Lite NGI-M08POE8-L2 Owner's Manual

Managed industrial gigabit ethernet switch
Table of Contents

Advertisement

7.1.3 ARP Inspection

Dynamic ARP inspection is a security feature which validates ARP packet in a network by
performing IP to MAC address binding inspection. Those will be stored in a trusted database (the
DHCP snooping database) before forwarding. Dynamic ARP intercepts, logs, and discards ARP
packets with invalid IP-to-MAC address bindings. This capability protects the network from
certain man-in-the-middle attacks.
Dynamic ARP inspection ensures that only valid ARP requests and responses are relayed.The
switch performs these activities:
Intercepts all ARP requests and responses on untrusted ports.
Verifies that each of these intercepted packets has a valid IP-to-MAC address binding before
it updates the local ARP cache or before it forwards the packet to the appropriate destination.
Trusted and Untrusted Port
This setting is independent of the trusted and untrusted setting of the DHCP Snooping.
The Switch does not discard ARP packets on trusted ports for any reasons.
The Switch discards ARP packets on un-trusted ports if the sender's information in the
ARP packets does not match any of the current bindings.
Normally, the trusted ports are the uplink port and the untrusted ports are connected to
subscribers.
Configurations:
Users can enable/disable the ARP Inspection on the Switch. Users also can enable/disable the
ARP Inspection on a specific VLAN. If the ARP Inspection on the Switch is disabled, the ARP
Inspection is disabled on all VLANs even some of the VLAN ARP Inspection are enabled.
Notices:
There are a global state and per VLAN states.
When the global state is disabled, the ARP Inspection on the Switch is disabled even per
VLAN states are enabled.
When the global state is enabled, user must enable per VLAN states to enable the ARP
Inspection on the specific VLAN.
7.1.3.1 ARP Inspection

7.1.3.1.1 CLI Configurations

Node
Command
enable
show arp-inspection
enable
configure terminal
configure
arp-inspection
(disable | enable)
configure
arp-inspection vlan
VLANLISTS
configure
no arp-inspection
vlan VLANLISTS
Description
This command displays the current ARP Inspection
configurations.
This command changes the node to configure node.
This command disables/enables the ARP Inspection
function on the switch.
This command enables the ARP Inspection function on a
VLAN or range of VLANs.
This command disables the ARP Inspection function on
a VLAN or range of VLANs.
260

Advertisement

Table of Contents
loading

Table of Contents