EasyManuals Logo
Home>Cisco>Firewall>FirePOWER ASA 5500 series

Cisco FirePOWER ASA 5500 series User Manual

Cisco FirePOWER ASA 5500 series
989 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #495 background imageLoading...
Page #495 background image
CHAPTER
26-1
Cisco Security Appliance Command Line Configuration Guide
OL-10088-01
26
Configuring ARP Inspection and Bridging
Parameters
Transparent Firewall Mode Only
This chapter describes how to enable ARP inspection and how to customize bridging operations for the
security appliance. In multiple context mode, the commands in this chapter can be entered in a security
context, but not the system.
This chapter includes the following sections:
• Configuring ARP Inspection, page 26-1
• Customizing the MAC Address Table, page 26-3
Configuring ARP Inspection
This section describes ARP inspection and how to enable it, and includes the following topics:
• ARP Inspection Overview, page 26-1
• Adding a Static ARP Entry, page 26-2
• Enabling ARP Inspection, page 26-2
ARP Inspection Overview
By default, all ARP packets are allowed through the security appliance. You can control the flow of ARP
packets by enabling ARP inspection.
When you enable ARP inspection, the security appliance compares the MAC address, IP address, and
source interface in all ARP packets to static entries in the ARP table, and takes the following actions:
• If the IP address, MAC address, and source interface match an ARP entry, the packet is passed
through.
• If there is a mismatch between the MAC address, the IP address, or the interface, then the security
appliance drops the packet.
• If the ARP packet does not match any entries in the static ARP table, then you can set the security
appliance to either forward the packet out all interfaces (flood), or to drop the packet.

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco FirePOWER ASA 5500 series and is the answer not in the manual?

Cisco FirePOWER ASA 5500 series Specifications

General IconGeneral
BrandCisco
ModelFirePOWER ASA 5500 series
CategoryFirewall
LanguageEnglish

Related product manuals