Switch User Manual
set arpinspection trust
SecureStack C3 Configuration Guide 17-21
Parameters
Defaults
Loggingisdisabledbydefault.
Mode
Switchcommand,read‐write.
Usage
ThiscommandenablesdynamicARPinspection(DAI)ononeormoreVLANs.WhenDAIis
enabledonaVLAN,DAIiseffectivelyenabledontheinterfaces(physicalportsorLAGs)thatare
membersofthatVLAN.
DAIusestheDHCPsnoopingbindingsdatabasetoverifythatthesenderMACaddressand
the
sourceIPaddressareavalidpairinthedatabase.ARPpacketswhosesenderMACaddressand
senderIPaddressdonotmatchanentryinthedatabasearedropped.
Ifloggingisenabled,invalidARPpacketsarealsologged.
Example
ThisexampleenablesDAIonVLANs2through5andalsoenablesloggingofinvalidARPpackets
onthoseVLANs.
C3(su)->set arpinspection vlan 2-5 logging
set arpinspection trust
UsethiscommandtoenableordisableaportasadynamicARPinspectiontrustedport.
Syntax
set arpinspection trust port port-string {enable | disable}
Parameters
Defaults
Bydefault,allphysicalportsandLAGsareuntrusted.
Mode
Switchcommand,read‐write.
vlan‐range SpecifiestheVLANorrangeofVLANsonwhichtoenabledynamic
ARPinspection.
logging (Optional)EnablesloggingofinvalidARPpacketsforthatVLAN.
port‐string SpecifiestheportorportstobeenabledordisabledasDAItrusted
ports.TheportscanbephysicalportsorLAGsthataremembersofa
VLAN.
enable|disable EnablesordisablesthespecifiedportsastrustedforDAI.