Table 56: Arp Inspection Commands - Edge-Core ECS4210-12P Reference Manual

12/28-port gigabit ethernet layer 2 switch
Hide thumbs Also See for ECS4210-12P:
Table of Contents

Advertisement

ARP Inspection
Example
Console#show ip source-guard binding
MacAddress
IpAddress
----------------- --------------- ---------- -------------------- ---- --------
11-22-33-44-55-66 192.168.0.99
Console#
ARP Inspection validates the MAC-to-IP address bindings in Address Resolution
Protocol (ARP) packets. It protects against ARP traffic with invalid address bindings,
which forms the basis for certain "man-in-the-middle" attacks. This is accomplished
by intercepting all ARP requests and responses and verifying each of these packets
before the local ARP cache is updated or the packet is forwarded to the appropriate
destination, dropping any invalid ARP packets.
ARP Inspection determines the validity of an ARP packet based on valid IP-to-MAC
address bindings stored in a trusted database – the DHCP snooping binding
database. ARP Inspection can also validate ARP packets against user-configured
ARP access control lists (ACLs) for hosts with statically configured IP addresses.
This section describes commands used to configure ARP Inspection.

Table 56: ARP Inspection Commands

Command
ip arp inspection
ip arp inspection filter
ip arp inspection log-buffer
logs
ip arp inspection validate
ip arp inspection vlan
ip arp inspection limit
ip arp inspection trust
show ip arp inspection
configuration
show ip arp inspection
interface
show ip arp inspection log
Chapter 8
Lease(sec) Type
0 Static
Function
Enables ARP Inspection globally on the switch
Specifies an ARP ACL to apply to one or more VLANs
Sets the maximum number of entries saved in a log
message, and the rate at these messages are sent
Specifies additional validation of address components in
an ARP packet
Enables ARP Inspection for a specified VLAN or range of
VLANs
Sets a rate limit for the ARP packets received on a port
Sets a port as trusted, and thus exempted from ARP
Inspection
Displays the global configuration settings for ARP
Inspection
Shows the trust status and inspection rate limit for ports PE
Shows information about entries stored in the log,
including the associated VLAN, port, and address
components
– 285 –
| General Security Measures
ARP Inspection
VLAN Interface
1 Eth 1/5
Mode
GC
GC
GC
GC
GC
IC
IC
PE
PE

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ecs4210-12tEcs4210-28pEcs4210-28t

Table of Contents