Security
ARP Inspection
STEP 1
STEP 2
STEP 3
STEP 4
Cisco Small Business 200, 300 and 500 Series Managed Switch Administration Guide (Internal Version)
Interaction Between ARP Inspection and DHCP Snooping
If DHCP Snooping is enabled, ARP Inspection uses the DHCP Snooping Binding
database in addition to the ARP access control rules. If DHCP Snooping is not
enabled, only the ARP access control rules are used.
ARP Defaults
The following table describes the ARP defaults:
Option
Dynamic ARP Inspection
ARP Packet Validation
ARP Inspection Enabled on
VLAN
Log Buffer Interval
ARP Inspection Work Flow
To configure ARP Inspection:
Enable ARP Inspection and configure various options in the Security > ARP
Inspection > Properties page.
Configure interfaces as ARP trusted or untrusted in the Security > ARP Inspection
> Interface Setting page.
Add rules in the Security > ARP Inspection > ARP Access Control and ARP Access
Control Rules pages.
Define the VLANs on which ARP Inspection is enabled and the Access Control
Rules for each VLAN in the Security > ARP Inspection > VLAN Settings page.
Defining ARP Inspection Properties
To configure ARP Inspection:
Default State
Not enabled.
Not enabled
Not enabled
SYSLOG message generation for
dropped packets is enabled at 5
seconds interval
18
373