Chapter 25 IP Source Guard

 

Table 76 ARP Inspection VLAN Configure (continued)

 

LABEL

DESCRIPTION

 

VID

This field displays the VLAN ID of each VLAN in the range specified

 

 

above. If you configure the * VLAN, the settings are applied to all

 

 

VLANs.

 

 

 

 

Enabled

Select Yes to enable ARP inspection on the VLAN. Select No to disable

 

 

ARP inspection on the VLAN.

 

 

 

 

Log

Specify when the Switch generates log messages for receiving ARP

 

 

packets from the VLAN.

 

 

None: The Switch does not generate any log messages when it

 

 

receives an ARP packet from the VLAN.

 

 

Deny: The Switch generates log messages when it discards an ARP

 

 

packet from the VLAN.

 

 

Permit: The Switch generates log messages when it forwards an ARP

 

 

packet from the VLAN.

 

 

All: The Switch generates log messages every time it receives an ARP

 

 

packet from the VLAN.

 

 

 

 

Apply

Click Apply to save your changes to the Switch’s run-time memory. The

 

 

Switch loses these changes if it is turned off or loses power, so use the

 

 

Save link on the top navigation panel to save your changes to the non-

 

 

volatile memory when you are done configuring.

 

 

 

 

Cancel

Click this to reset the values in this screen to their last-saved values.

 

 

 

25.10 Technical Reference

This section provides technical background information on the topics discussed in this chapter.

25.10.1 DHCP Snooping Overview

Use DHCP snooping to filter unauthorized DHCP packets on the network and to build the binding table dynamically. This can prevent clients from getting IP addresses from unauthorized DHCP servers.

25.10.1.1 Trusted vs. Untrusted Ports

Every port is either a trusted port or an untrusted port for DHCP snooping. This setting is independent of the trusted/untrusted setting for ARP inspection. You can also specify the maximum number for DHCP packets that each port (trusted or untrusted) can receive each second.

 

241

GS2200-24 User’s Guide