Administrator Guide

Table Of Contents
Layer 2 Switching Commands 378
Dynamic ARP Inspection
Commands
Dell Networking N1500/N2000/N3000/N4000 Series Switches
Dynamic ARP Inspection (DAI) is a security feature that rejects invalid and
malicious ARP packets. The feature prevents a class of man-in-the-middle
attacks, where an unfriendly station intercepts traffic for other stations by
poisoning the ARP caches of its neighbors. The attacker sends ARP requests
or responses mapping another station IP address to its own MAC address.
DAI drops ARP packets whose sender MAC address and sender IP address do
not match an entry in the DHCP Snooping bindings database.
Commands in this Section
This section explains the following commands:
arp access-list
Use the arp access-list command to create an ARP ACL. It will place the user
in ARP ACL Configuration mode. Use the “no” form of this command to
delete an ARP ACL.
Syntax
arp access-list
acl-name
no arp access-list
acl-name
acl-name
— A valid ARP ACL name (Range: 1–31 characters).
arp access-list ip arp inspection vlan
clear ip arp inspection statistics permit ip host mac host
ip arp inspection filter show arp access-list
ip arp inspection limit show ip arp inspection
ip arp inspection trust show ip arp inspection vlan
ip arp inspection validate
2CSNXXX_SWUM204.book Page 378 Monday, January 25, 2016 1:25 PM