Chapter4ServiceConīæguration
CommandFunction
zte(cfg)#setarp-inspectionvalidate{ip|dst-mac|src-mac}{enable|disable}
Enablesordisablestheinspectionof
eachīæeldofARPpacket.
zte(cfg)#setarp-inspectionvlan<vlanlist>{enable|disable}
EnablesordisablesDAIfunctionbased
onVLAN.
zte(cfg)#setarp-inspectionport<portlist>{trust|untrust}
Setsaporttoatrustedoruntrusted
port.
zte(cfg)#setarp-inspectionport<portlist>limit{<1-100>|infinite}
SetsthemaximumnumberofARP
packetsintheunittime.
showarp-inspection(allconīægurationmodes)
DisplaysDAIfunctionconīæguration
information.
DAIConīgurationInstance
lConīægurationDescription
AsshowninFigure4-19,whenDHCPsnoopingisenabled,checkARPpacketvalidity
andthecorrespondingrelationbetweenMAC,IPandVLAN.Illegalpacketisdropped
andtheratethatARPsendstoCPUofnon-trustedportislimited.
Figure4-19DAIConīægurationInstanceTopology
lConīægurationProcedure
zte(cfg)#setdhcpsnooping-and-option82enable
zte(cfg)#setdhcpsnoopingaddport49,50
zte(cfg)#setdhcpport49client
zte(cfg)#setdhcpport50server
zte(cfg)#showdhcpsnooping
DHCPsnoopingisenabledonthefollowingport(s):
PortIdPortType
--------------
49Client
50Server
4-65
SJ-20120409144109-002|2012-07-02(R1.0)ZTEProprietaryandConīædential