Netgear XSM4348CS CLI Manual Software Version 12.x - Page 547
Dynamic ARP Inspection Commands
![]() |
View all Netgear XSM4348CS manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 547 highlights
M4300 Intelligent Edge Series Fully Managed Stackable Switches Term Definition MAC Address The MAC address for the entry that is added. IP Address The IP address of the entry that is added. Type Entry type; statically configured from CLI or dynamically learned from DHCP Snooping. VLAN VLAN for the entry. Interface IP address of the interface in unit/slot/port format. Command example: (NETGEAR Switch) #show ip source binding MAC Address 00:00:00:00:00:08 00:00:00:00:00:09 00:00:00:00:00:0A IP Address 1.2.3.4 1.2.3.4 1.2.3.4 Type dhcp-snooping dhcp-snooping dhcp-snooping Vlan ----- 2 3 4 Interface 1/0/1 1/0/1 1/0/1 Dynamic ARP Inspection Commands Dynamic ARP Inspection (DAI) is a security feature that rejects invalid and malicious ARP packets. DAI prevents a class of man-in-the-middle attacks, where an unfriendly station intercepts traffic for other stations by poisoning the ARP caches of its unsuspecting neighbors. The miscreant sends ARP requests or responses mapping another station's IP address to its own MAC address. DAI relies on DHCP snooping. DHCP snooping listens to DHCP message exchanges and builds a binding database of valid MAC addresses, IP addresses, VLANs, and interfaces. When DAI is enabled, the switch drops ARP packets whose sender MAC address and sender IP address do not match an entry in the DHCP snooping bindings database. You can optionally configure additional ARP packet validation. ip arp inspection vlan Use this command to enable Dynamic ARP Inspection on a list of comma-separated VLAN ranges. Default Format Mode Disabled ip arp inspection vlan vlan-list Global Config Switching Commands 547 CLI Command Reference Manual
![](/manual_guide/products/netgear-m43008x8f-cli-manual-software-version-12x-6ae8ad6/547.png)