UMN:CLI

User Manual

 

SURPASS hiD 6615 S223/S323 R1.5

 

 

 

You can configure the switch to perform additional checks on the destination MAC ad- dress, the sender and target IP address and the source MAC address.

Command

 

Mode

Description

 

 

 

 

 

 

 

Inspects specific check on incoming ARP packets.

 

 

 

src-mac: checks the source MAC address. Packets

 

 

 

with different MAC addresses are classified as invalid

ip arp inspection validate {src-

 

are dropped.

mac dst-mac ip}

 

 

dst-mac: checks the destination MAC address. Packets

 

 

 

with different MAC addresses are classified as invalid

 

 

Global

are dropped.

 

 

ip: checks the unexpected IP address.

 

 

 

 

 

 

 

ip arp inspection filter

NAME

 

Applies ARP ACL to the VLAN.

 

NAME: ARP ACL name. It is created with the arp ac-

vlan VLAN

 

 

 

 

cess-list NAME command.

 

 

 

 

 

 

ip arp inspection trust port

 

Configures a connection between switches as trusted.

PORTS

 

 

PORTS: trusted port number.

 

 

 

 

To remove the specific ARP Inspection configuration, use the following commands

Command

 

Mode

Description

 

 

 

 

no ip arp inspection

validate

 

 

{src-mac dst-mac ip}

 

 

 

 

 

 

no ip arp inspection filter NAME

Global

Removes specific ARP inspection configuration.

vlan VLAN

 

 

 

 

 

 

 

no ip arp inspection trust port

 

 

PORTS

 

 

 

 

 

 

 

To display checking and statistics, use the following command.

Command

 

Mode

Description

 

 

 

show ip arp inspection [vlan

 

 

VLAN]

 

Enable

 

 

 

 

show ip arp inspection statistics

 

Global

Displays the information of ARP inspection.

[vlan VLAN]

 

 

Bridge

 

 

 

 

show ip arp inspection

trust

 

 

 

[port PORTS]

 

 

 

 

 

 

 

To clear ARP inspection mapping counter and statistics, use the following command.

Command

Mode

Description

 

 

 

clear ip arp inspection statistics

Global

Clears ARP inspection statistics.

[vlan VLAN]

Bridge

 

 

 

 

168

A50010-Y3-C150-2-7619

Page 168
Image 168
Siemens S323, S223 user manual 168 A50010-Y3-C150-2-7619