Dynamic Arp Inspection Functionality - Alaxala AX2200S Series Configuration Manual

Table of Contents

Advertisement

23 DHCP Snooping
DHCP packets exceeds the specified reception rate, this function discards the excess
DHCP packets.
You can set the reception rate by using the
command. If the reception rate is not set, it has no limit.
The rate of DHCP packet reception is limited only on untrusted ports, not on trusted ports.
DHCP packets exceeding the rate are dropped, and the incident is logged in the operation
log. However, traps are not issued. Use the
operation log information, and use the
command to check the number of discarded packets.
The collection of operation log information is triggered by the following events:
A Limit Exceeded event is collected when the configured reception rate is exceeded.
A Stable State event is collected after a Limit Exceeded event is collected and when
the reception rate continues below the configured reception rate limit for about 30
seconds ((1) in the figure).
During the period after the Limit Exceeded event is collected until the Stable State
event is collected ((2) in the figure), no event is collected even if packets are
discarded due to being in excess of the configured rate.
The following figure shows the events logged in the operation log.
Figure 23-7 Events logged in the operation log related to the rate of DHCP packet

23.1.5 Dynamic ARP inspection functionality

In this functionality, if DHCP snooping is enabled, the Switch checks whether the sender IP
address and sender MAC address in an ARP packet received on an untrusted port on the
Switch are those of a legitimate terminal registered in the binding database. This
functionality prevents a spoofed ARP packet sent from a terminal not registered in the DB,
from taking over communication of a legitimate terminal.
(1) Targets of dynamic ARP inspection
ARP packets that meet all the following conditions are subject to dynamic ARP inspection:
ARP packets received on ports belonging to the VLANs that are subject to ARP
inspection
(To set VLANs that are subject to ARP inspection, use the
configuration command.)
ARP packets received on untrusted ports (ports which have not been set as trusted
412
reception
ip dhcp snooping limit rate
show logging
operation command to check the
show ip dhcp snooping statistics
configuration
operation
ip arp inspection vlan

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ax1250s seriesAx1240s series

Table of Contents