2-619
Catalyst 6500 Series Switch Command Reference—Release8.4
OL-6244-01
Chapter2 Catalyst 6500 Series Switch and ROM Monitor Commands set security acl arp-inspection
The following MAC addresses are illegal:
00-00-00-00-00-00
Multicast MAC addresses
ff-ff-ff-ff-ff-ff
Note If you do not enter the drop keyword, the system only generates a syslog message.
The set security acl arp-inspection dynamic {enable | disable} vlanlist command enables or disables
DAI bindings for specified VLANs. The command does not affect any static ARP inspection rules that
are specified as part of the security ACL framework.
Do not enable DAI on a VLAN unless DHCP Snooping is also enabled on the VLAN. You cannot enable
DAI on management VLANs.
Do not enable DAI on VLANs that have ports with static IP addresses unless the ports are trusted.
If DAI is enabled for a VLAN that is untrusted for ARP inspection, the port should be untrusted for
DHCP snooping. Otherwise, all ARP packets from that port will be dropped because bindings are not
kept for ports trusted by DHCP snooping.
The set security acl arp-inspection dynamic log {enable | disable} command enables or disables the
logging of packets that have been denied because of dynamic bindings. If logging is enabled, all packets
dropped because of dynamic bindings are logged. If logging is disabled, these packet s are not l ogged .
DAI logging is configured on a global basis and does not affect per-ACE logging that is spec ified for
static bindings.
Examples This example shows how to enable the MAC address matching feature:
Console> (enable) set security acl arp-inspection match-mac enable
ARP Inspection match-mac feature enabled.
Console> (enable)
This example shows how to enable the address validation feature:
Console> (enable) set security acl arp-inspection address-validation enable
ARP Inspection address-validation feature enabled.
Console> (enable)
This example shows how to enable the dynamic ARP i nsp ec ti on fe atu re :
Console> (enable) set security acl arp-inspection dynamic enable 100
Dynamic ARP Inspection is enabled for vlan(s) 100.
Console> (enable)
This example shows how to enable the dynamic ARP inspection loggin g fea tur e:
Console> (enable) set security acl arp-inspection dynamic log enable
Dynamic ARP Inspection logging enabled.
Console> (enable)
Related Commands set po rt arp-inspection
set security acl ip