clear arpinspection validate
SecureStack C2 Configuration Guide 17-27
clear arpinspection validate
UsethiscommandtoremoveadditionaloptionalARPvalidationparametersthatwerepreviously
configured.
Syntax
clear arpinspection validate {[src-mac] [dst-mac] [ip]}
Parameters
Defaults
Allparametersareoptional,butatleastoneparametermustbespecified.
Mode
Switchcommand,read‐write.
Usage
ThiscommandremovespreviouslyconfiguredadditionalvalidationofARPpacketsbyDAI,
beyondthebasicvalidationthattheARPpacket’ssenderMACaddressandsenderIPaddress
matchanentryintheDHCPsnoopingbindingsdatabase.
Usetheshowarpinspectionvlancommandtodisplaythecurrentstatusoftheadditional
validation
rules.
Example
Thisexampleremovesall3additionalvalidationconditions.
C2(su)->clear arpinspection validate src-mac dst-mac ip
clear arpinspection vlan
UsethiscommandtodisabledynamicARPinspectionononeormoreVLANsortodisable
loggingofinvalidARPpacketsononeormoreVLANs.
Syntax
clear arpinspection vlan vlan-range [logging]
Parameters
src‐mac Clear,orremove,theverificationthatthesenderMACaddressequals
thesourceMACaddressintheEthernetheader.
dst‐mac Clear,orremove,theverificationthatthetargetMACaddressequals
thedestinationMACaddressinthe Ethernetheader.
ip Clear,orremove,checkingtheIPaddressanddroppingARP
packets
withaninvalidaddress.
vlan‐range SpecifiestheVLANorrangeofVLANsonwhichtodisabledynamic
ARPinspection.
logging (Optional)DisableloggingofinvalidARPpacketsforthespecified
VLANs.