11.07.2015 Views

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 2<strong>Catalyst</strong> <strong>3750</strong>-E <strong>and</strong> <strong>3560</strong>-E <strong>Switch</strong> <strong>Cisco</strong> <strong>IOS</strong> Comm<strong>and</strong>sip arp inspection vlan loggingUsage GuidelinesThe term logged means that the entry is placed into the log buffer <strong>and</strong> that a system message is generated.The acl-match <strong>and</strong> dhcp-bindings keywords merge with each other; that is, when you configure an ACLmatch, the DHCP bindings configuration is not disabled. Use the no form of the comm<strong>and</strong> to reset thelogging criteria to their defaults. If neither option is specified, all types of logging are reset to log whenARP packets are denied. These are the options:• acl-match—Logging on ACL matches is reset to log on deny.• dhcp-bindings—Logging on DHCP binding matches is reset to log on deny.If neither the acl-match or the dhcp-bindings keywords are specified, all denied packets are logged.The implicit deny at the end of an ACL does not include the log keyword. This means that when you usethe static keyword in the ip arp inspection filter vlan global configuration comm<strong>and</strong>, the ACLoverrides the DHCP bindings. Some denied packets might not be logged unless you explicitly specifythe deny ip any mac any log ACE at the end of the ARP ACL.ExamplesThis example shows how to configure ARP inspection on VLAN 1 to log packets that match the permitcomm<strong>and</strong>s in the ACL:<strong>Switch</strong>(config)# arp access-list test1<strong>Switch</strong>(config-arp-nacl)# permit request ip any mac any log<strong>Switch</strong>(config-arp-nacl)# permit response ip any any mac any any log<strong>Switch</strong>(config-arp-nacl)# exit<strong>Switch</strong>(config)# ip arp inspection vlan 1 logging acl-match matchlogYou can verify your settings by entering the show ip arp inspection vlan vlan-range privileged EXECcomm<strong>and</strong>.Related Comm<strong>and</strong>s Comm<strong>and</strong> Descriptionarp access-listDefines an ARP ACL.clear ip arp inspection log Clears the dynamic ARP inspection log buffer.ip arp inspection log-buffer Configures the dynamic ARP inspection logging buffer.show inventory logDisplays the configuration <strong>and</strong> contents of the dynamic ARPinspection log buffer.show inventory vlanvlan-rangeDisplays the configuration <strong>and</strong> the operating state of dynamic ARPinspection for the specified VLAN.OL-9776-08<strong>Catalyst</strong> <strong>3750</strong>-E <strong>and</strong> <strong>3560</strong>-E <strong>Switch</strong> Comm<strong>and</strong> Reference2-227

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!