Chapter 9
| General Security Measures
ARP Inspection
– 344 –
ip arp inspection This command enables ARP Inspection globally on the switch. Use the no form to
disable this function.
Syntax
[no] ip arp inspection
Default Setting
Disabled
Command Mode
Global Configuration
Command Usage
â—† When ARP Inspection is enabled globally with this command, it becomes active
only on those VLANs where it has been enabled with the ip arp inspection vlan
command.
â—† When ARP Inspection is enabled globally and enabled on selected VLANs, all
ARP request and reply packets on those VLANs are redirected to the CPU and
their switching is handled by the ARP Inspection engine.
â—† When ARP Inspection is disabled globally, it becomes inactive for all VLANs,
including those where ARP Inspection is enabled.
ip arp inspection validate Specifies additional validation of address components in
an ARP packet
GC
ip arp inspection vlan Enables ARP Inspection for a specified VLAN or range of
VLANs
GC
ip arp inspection limit Sets a rate limit for the ARP packets received on a port IC
ip arp inspection trust Sets a port as trusted, and thus exempted from ARP
Inspection
IC
show ip arp inspection
configuration
Displays the global configuration settings for ARP
Inspection
PE
show ip arp inspection
interface
Shows the trust status and inspection rate limit for ports PE
show ip arp inspection log Shows information about entries stored in the log,
including the associated VLAN, port, and address
components
PE
show ip arp inspection
statistics
Shows statistics about the number of ARP packets
processed, or dropped for various reasons
PE
show ip arp inspection vlan Shows configuration setting for VLANs, including ARP
Inspection status, the ARP ACL name, and if the DHCP
Snooping database is used after ACL validation is
completed
PE
Table 64: ARP Inspection Commands (Continued)
Command Function Mode