What's new in this document

The following table describes information added or modified in this guide for FastIron 08.0.95a.

Summary of Enhancements in FastIronRelease 08.0.95a

Feature Description Location
RUCKUS ICX 7550 Added support for RUCKUS ICX 7550 devices. —
Updates to address defects Minor updates on content throughout to address defects. All chapters.
Minor editorial updates Minor editorial updates were made throughout the Configuration Guide. All chapters.

The following table describes information added or modified in this guide for FastIron 08.0.95.

Summary of Enhancements in FastIronRelease 08.0.95

Feature Description Location
DHCPv4 and DHCPv6 Snooping Enhancements A number of changes and enhancements have been introduced for DHCP and DHCPv6 Snooping as a result of ACL rearchitecture. These inclue the following:
  • DHCP Snooping can be configured for a VLAN or VLANS even before the VLAN or VLANS are created. VLANs and DHCP Snooping configurations on the VLANS are not automatically deleted when the VLAN is deleted.
  • When DHCP Snooping is enabled, client and server packets are not allowed on same port.
  • DHCP Snooping can be configured on a maximum of 511 VLANs.
  • DHCP Snooping cannot be enabled for a VLAN that is a member of a VLAN group.
  • When configuring DHCP Snooping on a range of VLANs or multi-VLAN, there cannot not be any VLAN in the range that is a member of a VLAN group or any reserved VLAN.
  • For default VLAN ID changes,DHCPv4 and DHCPv6 snooping are not automatically configured on the new default VLAN, and must be re-applied on the new default VLAN. The DHCP Snooping configurations are not automatically configured on the new default VLAN 4000.
  • ACLs are supported on member ports of a VLAN on which DHCP snooping and Dynamic ARP Inspection (DAI) are enabled. In previous releases, these were mutually exclusive.
Refer to
IP Source Guard (IPSG) and SG ACL Enhancements A number of changes and enhancements have been introduced for IPSG ACLs. These include the following:
  • A new command has been introduced to bind an IPSG ACL to a port, VLAN, or interface for incoming traffic.
  • IPSG and SG ACL can be configured for the same port. IPSG and ACLs are supported together on the same device with certain limitations.
  • IPSG cannot be enabled on a per-port-per-VLAN basis.
  • If IPSG is configured for a specified port for a VLAN, it cannot be configured globally for the VLAN.
  • IPSG Snooping can be configured on a maximum of 511 VLANs.
  • RUCKUS devices do not support IPSG with ingress IPv4 ACLs for the same port, neither at VLAN-level, port-level, or across different levels.
  • IPSG and SG ACL can be configured for the same port.
  • To bind an IPSG ACL to an interface for incoming traffice, you must now use the ip sg-access-group command.
  • IPSG is not supported for VLAN groups. If upgrading from FastIron 08.0.92 to FastIron 08.0.95, IPSG is not configured for a VLAN group, even if this was previously configured.
  • IPSG is not supported for VE interfaces.
  • When a client moves from one port to another port in the same VLAN, the old snoop entry for the client MAC address is automatically updated. This occurs even when the client acquires a new IP address.
  • Duplicate IP entries across VLANS are allowed in the DHCP snooping table. When a client moves from one VLAN to another and acquires the same address, two snooping entries are maintained for the same MAC address and IP address.
  • Option-82 can be disabled or re-enabled on multiple VLANs or a range of VLANS using a single command, ip dhcp snooping relay information disable.
  • IPSG can be enabled on tagged ports or untagged ports in a VLAN.
Refer to IP Source Guard
DHCP Client on non-default Virtual Ethernet Ports The DHCP client can be enabled for a non-default Virtual Ethernet (VE) port. By default, the DHCP client is enabled for the default VE port. The DHCP client can also be enabled for a non-default VE port. Refer to Enabling the DHCP Client for a Specific VE Port
Dynamic ARP Inspection (DAI)Enhancements A number of changes and enhancements have been introduced for DAI as a result of ACL rearchitecture. These include the following:
  • DAI can be configured on a maximum of 511 VLANs.
  • The maximum number of static DAI entries that can be configured is 6000. This value cannot be changed.
Refer to Dynamic ARP Inspection
Updates to address defects Minor updates on content throughout to address defects. All chapters.
Minor editorial updates Minor editorial updates were made throughout the Configuration Guide. All chapters.