Logging Of Dropped Packets; Configuring Dynamic Arp Inspection; Default Dynamic Arp Inspection Configuration - Cisco Catalyst 3750-X Software Configuration Manual

Hide thumbs Also See for Catalyst 3750-X:
Table of Contents

Advertisement

Chapter 25

Configuring Dynamic ARP Inspection

Logging of Dropped Packets

When the switch drops a packet, it places an entry in the log buffer and then generates system messages
on a rate-controlled basis. After the message is generated, the switch clears theentry from the log buffer.
Each log entry contains flow information, such as the receiving VLAN, the port number, the source and
destination IP addresses, and the source and destination MAC addresses.
You use the ip arp inspection log-buffer global configuration command to configure the number of
entries in the buffer and the number of entries needed in the specified interval to generate system
messages. You specify the type of packets that are logged by using the ip arp inspection vlan logging
global configuration command. For configuration information, see the
section on page
Configuring Dynamic ARP Inspection

Default Dynamic ARP Inspection Configuration

Table 25-1
Feature
Dynamic ARP inspection
Interface trust state
Rate limit of incoming ARP packets The rate is 15 pps on untrusted interfaces, assuming that the
ARP ACLs for non-DHCP
environments
Validation checks
OL-21521-01
25-13.
Default Dynamic ARP Inspection Configuration, page 25-5
Dynamic ARP Inspection Configuration Guidelines, page 25-6
Configuring Dynamic ARP Inspection in DHCP Environments, page 25-7
environments)
Configuring ARP ACLs for Non-DHCP Environments, page 25-8
environments)
Limiting the Rate of Incoming ARP Packets, page 25-10
Performing Validation Checks, page 25-12
Configuring the Log Buffer, page 25-13
Default Dynamic ARP Inspection Configuration
(optional)
(optional)
(optional)
Default Setting
Disabled on all VLANs.
All interfaces are untrusted.
network is a switched network with a host connecting to as many
as 15 new hosts per second.
The rate is unlimited on all trusted interfaces.
The burst interval is 1 second.
No ARP ACLs are defined.
No checks are performed.
Catalyst 3750-X and 3560-X Switch Software Configuration Guide
Configuring Dynamic ARP Inspection
"Configuring the Log Buffer"
(required in DHCP
(required in non-DHCP
25-5

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 3560-x

Table of Contents