Configuring Dynamic ARP Inspection
You must first configure static ARP or ARP inspection entry for hosts configured with a static IP address. Otherwise, when DAI checks ARP packets from these hosts against entries in the ARP table, it will not find any entries for them, and the RUCKUS device will not allow or learn ARP from an untrusted host.
Complete the following steps to configure DAI.
- Enter global configuration mode.
- (Optional) Configure an ARP
inspection entry only if there are hosts configured with a static IP address.
This command defines an ARP inspection entry in the static ARP table and maps the device IP address 10.20.20.12 with its MAC address, 0000.0002.0003. The ARP entry will be moved to the ARP table once the DAI receives a valid ARP packet with the matching IP and MAC addresses on a device port. Until then, the ARP entry will remain in Pend (pending) status.
Note: Dynamic ARP Inspection must be enabled to use static ARP inspection entries. - Enable Dynamic ARP Inspection on an existing VLAN.
The command enables DAI on VLAN 2. ARP packets from untrusted ports in VLAN 2 will undergo DAI.
- Enable trust on any ports that will bypass DAI.
- Enable DHCP snooping to populate the DHCP snooping IP-to-MAC address binding database.
The following example configures a DAI table entry, enables DAI on VLAN 2, and designates port 1/1/4 as trusted.
device# configure terminal device(config)# arp 10.20.20.12 0000.0002.0003 inspection device(config)# ip arp inspection vlan 2 device(config)# interface ethernet 1/1/4 device(config-if-e10000-1/1/4)# arp inspection trust