Dynamic Arp Inspection Commands; Commands In This Chapter; Arp Access-List - Dell PowerEdge M420 Reference Manual

Dell powerconnect m6220/m6348/m8024/m8024-k cli reference guide
Hide thumbs Also See for PowerEdge M420:
Table of Contents

Advertisement

Dynamic ARP Inspection
Commands
Dynamic ARP Inspection (DAI) is a security feature that rejects invalid and
malicious ARP packets. The feature prevents a class of man-in-the-middle
attacks, where an unfriendly station intercepts traffic for other stations by
poisoning the ARP caches of its neighbors. The miscreant sends ARP requests
or responses mapping another station IP address to its own MAC address.
DAI drops ARP packets whose sender MAC address and sender IP address do
not match an entry in the DHCP Snooping bindings database.

Commands in this Chapter

This chapter explains the following commands:

arp access-list

clear ip arp inspection statistics
ip arp inspection filter
ip arp inspection limit
ip arp inspection trust
ip arp inspection validate
arp access-list
Use the arp access-list command to create an ARP ACL. It will place the user
in ARP ACL Configuration mode. Use the "no" form of this command to
delete an ARP ACL.
Syntax
acl-name
arp access-list
no arp access-list
acl-name — A valid ARP ACL name (Range: 1–31 characters).
acl-name
ip arp inspection vlan
permit ip host mac host
show arp access-list
show ip arp inspection
show ip arp inspection vlan

Dynamic ARP Inspection Commands

13
341

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents