ip arp inspection validate
Enables validation of the ARP packet destination MAC, ARP Packet IP, and source MAC
addresses.
Command Default
IP ARP packet destination address validation is disabled.
Parameters
- dst-mac
- Checks the destination MAC address in the Ethernet header against the target MAC address in the ARP body for ARP responses. When enabled, packets with different MAC addresses are classified as invalid and are dropped.
- ip
- Checks the ARP body for invalid and unexpected IP addresses. Addresses include 0.0.0.0, 255.255.255.255, and all IP multicast addresses. Sender IP addresses are checked in all ARP requests and responses, and target IP addresses are checked only in ARP responses.
Modes
Global configuration mode
Usage Guidelines
You can enable validation of ARP packet destination addresses for a single destination address or for all destination addresses.
You must execute the command once for each type of ARP packet destination address you want to validate.
History
| Release version | Command history |
|---|---|
| 08.0.10a | This command was introduced. |