Configuring Dynamic Arp Inspection; Scenario One: Two Switches Support Dynamic Arp Inspection - Cisco 4500M Software Manual

Software guide
Table of Contents

Advertisement

Chapter 34
Understanding and Configuring Dynamic ARP Inspection

Configuring Dynamic ARP Inspection

This section includes these scenarios:

Scenario One: Two Switches Support Dynamic ARP Inspection

Assume that there are two switches, S1 and S2 with hosts H1 and H2 attached, respectively. Both S1 and
S2 are running DAI on VLAN 1 where the hosts are located. The S1 interface fa6/3 is connected to the
S2 interface fa3/3, and a DHCP server is connected to S1. Both hosts acquire their IP addresses from the
same DHCP server. Therefore, S1 has the binding for H1 and H2, and S2 has the binding for host H2.
To make the setup effective, you must configure the interface fa3/3 on S2 to be trusted. (You can leave
interface fa6/3 on S1 as untrusted.) If the DHCP server is moved from S1 to a different location, however,
the configuration will not work. To ensure that this setup works permanently, without compromising
security, you must configure both interfaces fa6/3 on S1 and fa3/3 on S2 as trusted.
Configuring Switch S1
To enable DAI and configure fa6/3 on S1 as trusted, follow these steps:
Verify the connection between switches S1 and S2:
Step 1
S1# show cdp neighbors
Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
Device ID
S2
S1#
Enable DAI on VLAN 1 and verify the configuration:
Step 2
S1# conf t
Enter configuration commands, one per line.
S1(config)# ip arp inspection vlan 1
S1(config)# end
S1# show ip arp inspection vlan 1
Source Mac Validation
Destination Mac Validation : Disabled
IP Address Validation
Vlan
----
Vlan
----
S1#
OL-6696-01
Scenario One: Two Switches Support Dynamic ARP Inspection, page 34-5
Scenario Two: One Switch Supports Dynamic ARP Inspection, page 34-9
S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone
Local Intrfce
Fas 6/3
Configuration
-------------
1
Enabled
ACL Logging
-----------
1
Deny
Holdtme
Capability
177
R S I
End with CNTL/Z.
: Disabled
: Disabled
Operation
ACL Match
---------
---------
Active
DHCP Logging
------------
Deny
Software Configuration Guide—Release 12.2(25)EW
Configuring Dynamic ARP Inspection
Platform
Port ID
WS-C4006
Fas 3/3
Static ACL
----------
34-5

Advertisement

Table of Contents
loading

This manual is also suitable for:

4500 series

Table of Contents