Netgear GS724Tv4 Software Administration Manual - Page 77

Con a DAI ACL, To con a DAI ACL with three rules and associate it with VLAN 100, System

Page 77 highlights

GS716Tv3, GS724Tv4, and GS748Tv5 Smart Switches Configure a DAI ACL DAI relies on the information in the DHCP snooping bindings database to validate ARP packets. For networks that use static IP addresses and do not use DHCP, DAI access control lists (ACLs) can be used to statically map an IP address to a MAC address on a VLAN. When hosts use static IP addresses, the DHCP snooping feature cannot build a bindings database. DAI ACLs are also useful when other switches in the network do not run DAI. DAI consults the static mappings configured in the DAI ACLs before it consults the DHCP snooping bindings database; thus static mappings have precedence over DHCP snooping bindings. If the static flag is enabled on a VLAN, DAI consults the DAI ACL only and does not validate ARP information against the DHCP snooping bindings database.  To configure a DAI ACL with three rules and associate it with VLAN 100: 1. Select System > Services > Dynamic ARP Inspection > DAI ACL Configuration. 2. In the Name field, specify a name for the ACL, for example arpACL. 3. Click the Add button. The screen displays the new ACL. 4. Click the ACL name, which is a hyperlink to the Dynamic ARP Inspection ACL Rules Configuration page. 5. From the ACL Name list, select the DAI ACL to configure. 6. In the Source IP Address field, specify the IP address of a host. 7. In the Source MAC Address field, specify the MAC address of the host that is statically mapped to the IP address specified in the Source IP Address field. 8. Click the Add button. 9. Repeat Step 6 through Step 8 to add the second rule. You can add up to 20 static IP address-MAC address mappings to a DAI ACL. Configure System Information 77

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290

Configure System Information
77
GS716Tv3, GS724Tv4, and GS748Tv5 Smart Switches
Configure a DAI ACL
DAI relies on the information in the DHCP snooping bindings database to validate ARP
packets. For networks that use static IP addresses and do not use DHCP, DAI access control
lists (ACLs) can be used to statically map an IP address to a MAC address on a VLAN. When
hosts use static IP addresses, the DHCP snooping feature cannot build a bindings database.
DAI ACLs are also useful when other switches in the network do not run DAI.
DAI consults the static mappings configured in the DAI ACLs before it consults the DHCP
snooping bindings database; thus static mappings have precedence over DHCP snooping
bindings. If the static flag is enabled on a VLAN, DAI consults the DAI ACL only and does not
validate ARP information against the DHCP snooping bindings database.
To configure a DAI ACL with three rules and associate it with VLAN 100:
1.
Select
System
>
Services
>
Dynamic ARP Inspection
>
DAI ACL Configuration
.
2.
In the Name field, specify a name for the ACL, for example arpACL.
3.
Click the
Add
button.
The screen displays the new ACL.
4.
Click the ACL name, which is a hyperlink to the Dynamic ARP Inspection ACL Rules
Configuration page.
5.
From the ACL Name list, select the DAI ACL to configure.
6.
In the Source IP Address field, specify the IP address of a host.
7.
In the Source MAC Address field, specify the MAC address of the host that is statically
mapped to the IP address specified in the Source IP Address field.
8.
Click the
Add
button.
9.
Repeat
Step 6
through
Step 8
to add the second rule.
You can add up to 20 static IP address-MAC address mappings to a DAI ACL.