Cisco 7604 Configuration Manual page 589

Ios software configuration guide
Hide thumbs Also See for 7604:
Table of Contents

Advertisement

Chapter 38
Configuring Dynamic ARP Inspection
Configuring Router A
To enable DAI and configure Fast Ethernet port 6/3 on Router A as trusted, follow these steps:
Step 1
Verify the connection between switches Router A and Router B:
RouterA# show cdp neighbors
Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
Device ID
RouterB
RouterA#
Step 2
Enable DAI on VLAN 1 and verify the configuration:
RouterA# configure terminal
Enter configuration commands, one per line.
RouterA(config)# ip arp inspection vlan 1
RouterA(config)# end
RouterA# show ip arp inspection vlan 1
Source Mac Validation
Destination Mac Validation : Disabled
IP Address Validation
Vlan
----
Vlan
----
RouterA#
Configure Fast Ethernet port 6/3 as trusted:
Step 3
RouterA# configure terminal
Enter configuration commands, one per line.
RouterA(config)# interface fastethernet 6/3
RouterA(config-if)# ip arp inspection trust
RouterA(config-if)# end
RouterA# show ip arp inspection interfaces fastethernet 6/3
Interface
---------------
Fa6/3
RouterA#
Verify the bindings:
Step 4
RouterA# show ip dhcp snooping binding
MacAddress
------------------
00:02:00:02:00:02
RouterA#
OL-4266-08
To ensure that this configuration does not compromise security, configure Fast Ethernet port 6/3 on
Router A and Fast Ethernet port 3/3 on Router B as trusted.
S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone
Local Intrfce
Fas 6/3
Configuration
-------------
1
Enabled
ACL Logging
-----------
1
Deny
Trust State
-----------
Trusted
IpAddress
---------------
1.1.1.2
Cisco 7600 Series Router Cisco IOS Software Configuration Guide, Release 12.2SX
Holdtme
Capability
177
R S I
End with CNTL/Z.
: Disabled
: Disabled
Operation
ACL Match
---------
---------
Active
DHCP Logging
------------
Deny
End with CNTL/Z.
Rate (pps)
----------
None
Lease(sec)
Type
----------
-------------
4993
dhcp-snooping
DAI Configuration Samples
Platform
Port ID
WS-C6506
Fas 3/3
Static ACL
----------
VLAN
Interface
----
--------------------
1
FastEthernet6/4
38-17

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

761376067609-s7600 series

Table of Contents