Alaxala AX2200S Series Configuration Manual page 448

Table of Contents

Advertisement

23 DHCP Snooping
inspection)
Points to note
Of the VLANs for which DHCP snooping is enabled, set the VLAN IDs of the VLANs
to be used for dynamic ARP inspection. ARP packets received in the specified
VLANs are subject to the basic inspection.
Command examples
1.
(config)# ip arp inspection vlan 2
Sets VLAN ID 2 as a VLAN subject to dynamic ARP inspection. Dynamic ARP
inspection will be performed only for VLANs for which this command is set.
Notes
1.
2.
3.
(2) Setting ports on which dynamic ARP inspection is not performed
Points to note
The following example configures this setting for a port for which dynamic ARP
inspection is not performed.
Command examples
1.
(config)# interface fastethernet 0/5
(config-if)# ip arp inspection trust
(config-if)# exit
Sets port 0/5 as the port on which dynamic ARP inspection is not performed. The
other ports are set as ports on which dynamic ARP inspection is performed.
Notes
1.
2.
(3) Setting the optional inspection of dynamic ARP inspection
Points to note
Set the optional inspection for the ARP packets for which the basic inspection was
performed. In this example, set the configuration so that inspection is performed to
check if the source MAC address and the sender MAC address of received ARP
packets are the same.
Command examples
1.
(config)# ip arp inspection validate src-mac
Sets the src-mac check that checks if the source MAC address and the sender MAC
address of received ARP packets are the same.
(4) Setting the rate of ARP packet reception
Points to note
The following example sets the reception rate of port 0/1 that receives ARP packets
from the terminal.
426
Specify the VLAN ID that was set by using the
configuration command.
If this command sets a VLAN ID for dynamic ARP inspection, the binding
database entries registered by the
command are also subject to dynamic ARP inspection.
If you use the
ip arp inspection trust
belonging to the VLANs for which this command has been set, dynamic ARP
inspection will not be performed on the port.
Even if the ports which have been set by this command belong to VLANs
subject to dynamic ARP inspection, dynamic ARP inspection will not be
performed for those ports.
The ARP packet reception rate of the ports set by this command has no limit.
ip dhcp snooping vlan
ip source binding
configuration
configuration command to set a port

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ax1250s seriesAx1240s series

Table of Contents