Configuring Dynamic ARP Inspection

Dynamic ARP Inspection is disabled by default and the trust setting of ports is untrusted by default.

You must first configure static ARP or ARP inspection entry for hosts configured with a static IP address. Otherwise, when DAI checks ARP packets from these hosts against entries in the ARP table, it will not find any entries for them, and the RUCKUS device will not allow or learn ARP from an untrusted host.

Complete the following steps to configure DAI.

  1. Enter global configuration mode.
    device# configure terminal
  2. (Optional) Configure an ARP inspection entry only if there are hosts configured with a static IP address.
    device(config)# arp 10.20.20.12 0000.0002.0003 inspection

    This command defines an ARP inspection entry in the static ARP table and maps the device IP address 10.20.20.12 with its MAC address, 0000.0002.0003. The ARP entry will be moved to the ARP table once the DAI receives a valid ARP packet with the matching IP and MAC addresses on a device port. Until then, the ARP entry will remain in Pend (pending) status.

    Note: Dynamic ARP Inspection must be enabled to use static ARP inspection entries.
  3. Enable Dynamic ARP Inspection.
    1. For all devices, you can enable Dynamic ARP Inspection on an existing VLAN
      device(config)# ip arp inspection vlan 2
      The command enables DAI on VLAN 2. ARP packets from untrusted ports in VLAN 2 will undergo DAI.
    2. (Optional) For ICX 8100 and ICX 8200 devices, Dynamic ARP Inspection can be enabled at the port level.
      device(config)# interface ethernet 1/1/4
      device(config-if-e10000-1/1/4)# ip arp inspection
      
      The command enables DAI on port 1/1/4.
  4. Enable trust on any ports that will bypass DAI.
    1. To enable trust on a port, enter interface configuration mode.
      device(config)# interface ethernet 1/1/4
    2. Enable trust on the port.
      device(config-if-e10000-1/1/4)# arp inspection trust
      These commands set the trust setting of port 1/1/4 to trusted.
  5. Enable DHCP snooping to populate the DHCP snooping IP-to-MAC address binding database.

The following example configures a DAI table entry, enables DAI on VLAN 2, and designates port 1/1/4 as trusted.

device# configure terminal
device(config)# arp 10.20.20.12 0000.0002.0003 inspection
device(config)# ip arp inspection vlan 2
device(config)# interface ethernet 1/1/4
device(config-if-e10000-1/1/4)# ip arp inspection
device(config)# interface ethernet 1/1/4
device(config-if-e10000-1/1/4)# arp inspection trust