11.07.2015 Views

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 2<strong>Catalyst</strong> <strong>3750</strong>-E <strong>and</strong> <strong>3560</strong>-E <strong>Switch</strong> <strong>Cisco</strong> <strong>IOS</strong> Comm<strong>and</strong>sip arp inspection filter vlanip arp inspection filter vlanUse the ip arp inspection filter vlan global configuration comm<strong>and</strong> on the switch stack or on ast<strong>and</strong>alone switch to permit or deny Address Resolution Protocol (ARP) requests <strong>and</strong> responses from ahost configured with a static IP address when dynamic ARP inspection is enabled. Use the no form ofthis comm<strong>and</strong> to return to the default settings.ip arp inspection filter arp-acl-name vlan vlan-range [static]no ip arp inspection filter arp-acl-name vlan vlan-range [static]Syntax Descriptionarp-acl-namevlan-rangestaticARP access control list (ACL) name.VLAN number or range.You can specify a single VLAN identified by VLAN ID number, a range ofVLANs separated by a hyphen, or a series of VLANs separated by a comma.The range is 1 to 4094.(Optional) Specify static to treat implicit denies in the ARP ACL as explicitdenies <strong>and</strong> to drop packets that do not match any previous clauses in theACL. DHCP bindings are not used.If you do not specify this keyword, it means that there is no explicit deny inthe ACL that denies the packet, <strong>and</strong> DHCP bindings determine whether apacket is permitted or denied if the packet does not match any clauses in theACL.DefaultsNo defined ARP ACLs are applied to any VLAN.Comm<strong>and</strong> ModesGlobal configurationComm<strong>and</strong> HistoryRelease12.2(35)SE2ModificationThis comm<strong>and</strong> was introduced.Usage GuidelinesWhen an ARP ACL is applied to a VLAN for dynamic ARP inspection, only the ARP packets withIP-to-MAC address bindings are compared against the ACL. If the ACL permits a packet, the switchforwards it. All other packet types are bridged in the ingress VLAN without validation.If the switch denies a packet because of an explicit deny statement in the ACL, the packet is dropped. Ifthe switch denies a packet because of an implicit deny statement, the packet is then compared againstthe list of DHCP bindings (unless the ACL is static, which means that packets are not compared againstthe bindings).Use the arp access-list acl-name global configuration comm<strong>and</strong> to define the ARP ACL or to addclauses to the end of a predefined list.OL-9776-08<strong>Catalyst</strong> <strong>3750</strong>-E <strong>and</strong> <strong>3560</strong>-E <strong>Switch</strong> Comm<strong>and</strong> Reference2-215

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!