Configuring Dynamic ARP Inspection on Multiple VLANs
Dynamic ARP Inspection (DAI) can be
enabled on multiple VLANs using one command. The following task configures multiple
VLANs
and enables DAI on most of the configured VLANs using a single command.
Complete the following steps to configure DAI for multiple VLANs.
Note: DAI can be configured on a maximum of 511 VLANs.
- Enter global configuration mode.
- Configure the port-based VLANs.
- Add port Ethernet 1/1/12 as a tagged port.
- Use the
exitcommand to return to global configuration mode. - Configure more port-based VLANs.
- Add port Ethernet 1/1/12 as a tagged port.
- Use the
exitcommand to return to global configuration mode. - Use the
ip arp inspectioncommand with the to keyword, specifying a VLAN range, to enable DAI on multiple VLANs. - Enable trust on any ports that will bypass DAI.
- Enable DHCP snooping to populate the DHCP snooping IP-to-MAC address binding database. Refer to the RUCKUS FastIron DHCP Configuration Guide for more information.
The following example configures a DAI table entry, configures multiple VLANs, and enables DAI on most of the configured VLANS. Port 1/1/12 is designated as trusted.
device# configure terminal device(config)# arp 10.20.20.12 0000.0002.0003 inspection device(config)# vlan 100 to 150 device(config-mvlan-100-150)# tagged ethernet 1/1/12 device(config-mvlan-100-150)# exit device(config)# vlan 151 to 200 device(config-mvlan-151-200)# tagged ethernet 1/1/12 device(config-mvlan-100-150)# exit device(config)# ip arp inspection vlan 100 to 150 160 170 to 200 device(config)# interface ethernet 1/1/12 device(config-if-e10000-1/1/12)# arp inspection trust