Specifications

clear dhcpsnooping limit
18-16 DHCP Snooping and Dynamic ARP Inspection
clear dhcpsnooping limit
Usethiscommandtoresettheratelimitvaluestothedefaultsof15packetspersecondwitha
burstintervalof1second.
Syntax
clear dhcpsnooping limit port-string
Parameters
Defaults
None.
Mode
Switchcommand,readwrite.
Example
Thisexampleresetstheratelimitvaluestotheirdefaultsonportge.1.1.
B2
(su)->clear dhcpsnooping limit ge.1.1
Dynamic ARP Inspection Overview
DynamicARPinspection(DAI)isasecurityfeaturethatrejectsinvalidandmaliciousARP
packets.Thefeaturepreventsaclassofmaninthemiddleattackswhereanunfriendlystation
interceptstrafficforotherstationsbypoisoningtheARPcachesofitsunsuspectingneighbors.
ARPpoisoningisatacticwherean
attackerinjectsfalseARPpacketsintothesubnet,normallyby
broadcastingARPresponsesinwhichtheattackerclaimstobe someoneelse.Bypoisoningthe
ARPcache,amalicioususercaninterceptthetrafficintendedforotherhostsonthenetwork.
TheDynamicARPInspectionapplicationperformsARPpacketvalidation.
WhenDAIisenabled,
itverifiesthatthesenderMACaddressandthesourceIPaddressareavalidpairintheDHCP
snoopingbindingdatabaseanddropsARPpacketswhosesenderMACaddressandsenderIP
addressdonotmatchanentryinthedatabase.AdditionalARPpacketvalidationcan
be
configured.
IfDHCPsnoopingisdisabledontheingressVLANorthereceiveinterfaceistrustedforDHCP
snooping,ARPpacketsaredropped.
Functional Description
DAIisenabledonVLANs,effectivelyenablingDAIontheinterfaces(physicalportsorLAGs)that
aremembersofthatVLAN.Individualinterfacesareconfiguredastrustedoruntrusted.Thetrust
configurationforDAIisindependentofthetrustconfigurationforDHCPsnooping.Atrusted
portisaportthenetwork
administratordoesnotconsidertobeasecuritythreat.Anuntrusted
portisonewhichcouldpotentiallybeusedtolaunchanetworkat tack.
DAIconsidersallphysicalportsandLAGsuntrustedbydefault.
portstring Specifiestheportorportstowhichthiscommandapplies.