58 Command Groups
Dynamic ARP Inspection
Command Description Mode*
arp access-list Creates an ARP ACL. GC
clear counters ip arp inspection Resets the statistics for Dynamic ARP Inspection on all
VLANs.
PE
ip arp inspection filter Configures the ARP ACL to be used for a single VLAN or a
range of VLANs to filter invalid ARP packets.
GC
ip arp inspection limit Configures the rate limit and burst interval values for an
interface.
IC
ip arp inspection trust Configures an interface as trusted for Dynamic ARP
Inspection.
IC
ip arp inspection validate Enables additional validation checks like source MAC
address validation, destination MAC address validation or
IP address validation on the received ARP packets.
GC
ip arp inspection vlan Enables Dynamic ARP Inspection on a single VLAN or a
range of VLANs.
GC
permit ip host mac host Configures a rule for a valid IP address and MAC address
combination used in ARP packet validation.
ARPA
show arp access-list Displays the configured ARP ACLs with the rules. PE
show ip arp inspection ethernet Displays the Dynamic ARP Inspection configuration on all
the DAI enabled interfaces.
PE
show ip arp inspection statistics Displays the statistics of the ARP packets processed by
Dynamic ARP Inspection.
PE
show ip arp inspection vlan Displays the Dynamic ARP Inspection configuration on all
the VLANs in the given VLAN range.
PE
*NOTE: For the meaning of each Mode abbreviation, see "Mode Types" on page 51.