11.07.2015 Views

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 2<strong>Catalyst</strong> <strong>3750</strong>-E <strong>and</strong> <strong>3560</strong>-E <strong>Switch</strong> <strong>Cisco</strong> <strong>IOS</strong> Comm<strong>and</strong>sip arp inspection validateip arp inspection validateUse the ip arp inspection validate global configuration comm<strong>and</strong> on the switch stack or on a st<strong>and</strong>aloneswitch to perform specific checks for dynamic Address Resolution Protocol (ARP) inspection. Use theno form of this comm<strong>and</strong> to return to the default settings.ip arp inspection validate {[src-mac] [dst-mac] [ip [allow zeros] ]}no ip arp inspection validate [src-mac] [dst-mac] [ip [allow zeros] ]This comm<strong>and</strong> is available only if your switch is running the IP services feature set.Syntax Descriptionsrc-macdst-macipallow-zerosCompare the source MAC address in the Ethernet header against the sender MACaddress in the ARP body. This check is performed on both ARP requests <strong>and</strong>responses.When enabled, packets with different MAC addresses are classified as invalid <strong>and</strong> aredropped.Compare the destination MAC address in the Ethernet header against the target MACaddress in ARP body. This check is performed for ARP responses.When enabled, packets with different MAC addresses are classified as invalid <strong>and</strong> aredropped.Compare the ARP body for invalid <strong>and</strong> unexpected IP addresses. Addresses include0.0.0.0, 255.255.255.255, <strong>and</strong> all IP multicast addresses.Sender IP addresses are compared in all ARP requests <strong>and</strong> responses. Target IPaddresses are checked only in ARP responses.Modifies the IP validation test so that ARPs with a sender address of 0.0.0.0 (ARPprobes) are not denied.DefaultsNo checks are performed.Comm<strong>and</strong> ModesGlobal configurationComm<strong>and</strong> HistoryRelease12.2(35)SE212.2(37)SEModificationThis comm<strong>and</strong> was introduced.The allow-zero keyword was added.OL-9776-08<strong>Catalyst</strong> <strong>3750</strong>-E <strong>and</strong> <strong>3560</strong>-E <strong>Switch</strong> Comm<strong>and</strong> Reference2-223

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!