Cisco WS-CBS3032-DEL Software Configuration Manual page 587

Software guide
Table of Contents

Advertisement

Chapter 23
Configuring Dynamic ARP Inspection
Beginning in privileged EXEC mode, follow these steps to configure an ARP ACL on Switch A. This
procedure is required in non-DHCP environments.
Command
Step 1
configure terminal
Step 2
arp access-list acl-name
Step 3
permit ip host sender-ip mac host sender-mac [log]
Step 4
exit
Step 5
ip arp inspection filter arp-acl-name vlan vlan-range
[static]
Step 6
interface interface-id
OL-13270-06
Purpose
Enter global configuration mode.
Define an ARP ACL, and enter ARP access-list
configuration mode. By default, no ARP access lists
are defined.
Note
Permit ARP packets from the specified host (Host 2).
Return to global configuration mode.
Apply the ARP ACL to the VLAN. By default, no
defined ARP ACLs are applied to any VLAN.
ARP packets containing only IP-to-MAC address
bindings are compared against the ACL. Packets are
permitted only if the access list permits them.
Specify the Switch A interface that is connected to
Switch B, and enter interface configuration mode.
Cisco Catalyst Blade Switch 3130 and 3032 for Dell Software Configuration Guide
Configuring Dynamic ARP Inspection
At the end of the ARP access list, there is an
implicit deny ip any mac any command.
For sender-ip, enter the IP address of Host 2.
For sender-mac, enter the MAC address of
Host 2.
(Optional) Specify log to log a packet in the log
buffer when it matches the access control entry
(ACE). Matches are logged if you also configure
the matchlog keyword in the ip arp inspection
vlan logging global configuration command. For
more information, see the
Buffer" section on page
23-13.
For arp-acl-name, specify the name of the ACL
created in Step 2.
For vlan-range, specify the VLAN that the
switches and hosts are in. You can specify a
single VLAN identified by VLAN ID number, a
range of VLANs separated by a hyphen, or a
series of VLANs separated by a comma. The
range is 1 to 4094.
(Optional) Specify static to treat implicit denies
in the ARP ACL as explicit denies and to drop
packets that do not match any previous clauses in
the ACL. DHCP bindings are not used.
If you do not specify this keyword, it means that
there is no explicit deny in the ACL that denies
the packet, and DHCP bindings determine
whether a packet is permitted or denied if the
packet does not match any clauses in the ACL.
"Configuring the Log
23-9

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst blade 3130Catalyst blade 3032

Table of Contents