hit counter script

Configuring Dynamic Arp Inspection; Default Dynamic Arp Inspection Configuration - Cisco Catalyst 2928 Software Configuration Manual

Ios release 12.2(55)ez
Table of Contents

Advertisement

Chapter 20

Configuring Dynamic ARP Inspection

Configuring Dynamic ARP Inspection

Default Dynamic ARP Inspection Configuration

Table 20-1
Table 20-1
Feature
Dynamic ARP inspection
Interface trust state
Rate limit of incoming ARP packets
ARP ACLs for non-DHCP environments
Validation checks
Log buffer
Per-VLAN logging
OL-23389-01
Default Dynamic ARP Inspection Configuration, page 20-5
Dynamic ARP Inspection Configuration Guidelines, page 20-6
Configuring Dynamic ARP Inspection in DHCP Environments, page 20-7
environments)
Configuring ARP ACLs for Non-DHCP Environments, page 20-8
environments)
Limiting the Rate of Incoming ARP Packets, page 20-10
Performing Validation Checks, page 20-11
Configuring the Log Buffer, page 20-12
shows the default dynamic ARP inspection configuration.
Default Dynamic ARP Inspection Configuration
Configuring Dynamic ARP Inspection
(required in non-DHCP
(optional)
(optional)
(optional)
Default Setting
Disabled on all VLANs.
All interfaces are untrusted.
The rate is 15 pps on untrusted interfaces, assuming that
the network is a switched network with a host
connecting to as many as 15 new hosts per second.
The rate is unlimited on all trusted interfaces.
The burst interval is 1 second.
No ARP ACLs are defined.
No checks are performed.
When dynamic ARP inspection is enabled, all denied or
dropped ARP packets are logged.
The number of entries in the log is 32.
The number of system messages is limited to 5 per
second.
The logging-rate interval is 1 second.
All denied or dropped ARP packets are logged.
Catalyst 2928 Switch Software Configuration Guide
(required in DHCP
20-5

Advertisement

Table of Contents
loading

Table of Contents