Chapter17SecurityConguration
DAIConfigurationExample
AsshowninFigure40,VLAN2isconguredonswitchandDAIis
run.
FIGURE40DAICONFIGURATIONEXAMPLE
Prerequisites:DHCPSNOOPINGfunctionisopenedinVLAN2.
ZXR10(config)#ipdhcpsnoopingenable
ZXR10(config)#ipdhcpsnoopingvlan2
VLAN2isconguredonswitchAandDAIisrun.
ZXR10(config-vlan2)#iparpinspection
Gei_1/1andgei_1/2areboundwithVLAN2.
Gei_1/1issetasuntrustedinterface(thedefaultattributeisun-
trustedinterface).
ThelegalARPpacket(legalARPpacket:consistentwitchIP+port+
MACinDHCPbindingtable)thathostAsendstoswitchisbroad-
castinVLAN.HostBcanreceiveARPpacket.Theillegalpacketis
discardedandnotforwarded.HostBcan’treceiveARPpacket.
Ifgei_1/1issetastrustedinterface,
hostAsendsARPpacket(legal/illegal)toswitch.Switchforwards
ARPpacketbyhardwaretoallinterfacesthatareboundwithVLAN
1.HostBcanreceiveARPpacket.Whenconguringinterfacelim-
CondentialandProprietaryInformationofZTECORPORATION179