ProSafe M4100 and M7100 Managed Switches

3.Configure the port through which the DHCP server is reached as trusted.

(Netgear Switch) (Config)# interface 1/0/1

(Netgear Switch) (Interface 1/0/1)# ip dhcp snooping trust

4.View the DHCP Snooping Binding table.

(GSM7328S) #show ip dhcp snooping binding

 

 

 

 

Total number

of bindings:

1

 

 

 

 

MAC

Address

IP Address

VLAN

Interface

Type

Lease (Secs)

-----------------

---------------

----

-----------

-------

-----------

00:16:76:A7:88:CC

192.168.10.86

1

1/0/2

DYNAMIC

86400

5.Enable ARP inspection in VLAN 1.

(Netgear Switch) (Config)# ip arp inspection vlan 1

Now all ARP packets received on ports that are members of the VLAN are copied to the CPU for ARP inspection. If there are trusted ports, you can configure them as trusted in the next step. ARP packets received on trusted ports are not copied to the CPU.

6.Configure port 1/0/1 as trusted.

(Netgear Switch) (Config)# interface 1/0/1

(Netgear Switch) (Interface 1/0/1)# ip arp inspection trust

Now ARP packets from the DHCP client go through because there is a DHCP snooping entry; however ARP packets from the static client are dropped. It can be overcome by static configuration as described in Static Mapping on page 303.

Web Interface: Configure Dynamic ARP Inspection

1.Enable DHCP snooping globally.

a. Select Security > Control > DHCP Snooping Global Configuration.

Chapter 15. Security Management 299

Page 299
Image 299
NETGEAR M4100, M7100 manual Web Interface Configure Dynamic ARP Inspection, View the Dhcp Snooping Binding table