Cisco WS-CBS3032-DEL Software Configuration Manual page 589

Software guide
Table of Contents

Advertisement

Chapter 23
Configuring Dynamic ARP Inspection
For configuration guidelines for rate limiting trunk ports and EtherChannel ports, see the
Inspection Configuration Guidelines" section on page
Beginning in privileged EXEC mode, follow these steps to limit the rate of incoming ARP packets. This
procedure is optional.
Command
Step 1
configure terminal
Step 2
interface interface-id
Step 3
ip arp inspection limit {rate pps [burst
interval seconds] | none}
Step 4
exit
Step 5
errdisable detect cause arp-inspection
and
errdisable recovery cause
arp-inspection
and
errdisable recovery interval interval
Step 6
exit
Step 7
show ip arp inspection interfaces
show errdisable recovery
Step 8
copy running-config startup-config
To return to the default rate-limit configuration, use the no ip arp inspection limit interface
configuration command. To disable error recovery for dynamic ARP inspection, use the no errdisable
recovery cause arp-inspection global configuration command.
OL-13270-06
Purpose
Enter global configuration mode.
Specify the interface to be rate-limited, and enter interface configuration
mode.
Limit the rate of incoming ARP requests and responses on the interface.
The default rate is 15 pps on untrusted interfaces and unlimited on
trusted interfaces. The burst interval is 1 second.
The keywords have these meanings:
For rate pps, specify an upper limit for the number of incoming
packets processed per second. The range is 0 to 2048 pps.
(Optional) For burst interval seconds, specify the consecutive
interval in seconds, over which the interface is monitored for a high
rate of ARP packets.The range is 1 to 15.
For rate none, specify no upper limit for the rate of incoming ARP
packets that can be processed.
Return to global configuration mode.
(Optional) Enable error recovery from the dynamic ARP inspection
error-disabled state, and configure the dynamic ARP inspection recover
mechanism variables
By default, recovery is disabled, and the recovery interval is 300
seconds.
For interval interval, specify the time in seconds to recover from the
error-disabled state. The range is 30 to 86400.
Return to privileged EXEC mode.
Verify your settings.
(Optional) Save your entries in the configuration file.
Cisco Catalyst Blade Switch 3130 and 3032 for Dell Software Configuration Guide
Configuring Dynamic ARP Inspection
23-6.
"Dynamic ARP
23-11

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst blade 3130Catalyst blade 3032

Table of Contents