Zyxel OLT2412 [188/326] Arp inspection command examples

Zyxel OLT2412 [188/326] Arp inspection command examples
Chapter 25 IP Source Guard
OLT2412 User’s Guide
188
25.7 ARP Inspection Command Examples
This example looks at the current list of MAC address filters that were created because the OLT
identified an unauthorized ARP packet. When the OLT identifies an unauthorized ARP packet, it
automatically creates a MAC address filter to block traffic from the source MAC address and source
VLAN ID of the unauthorized ARP packet.
The following table describes the labels in this display.
Table 102 ARP Inspection VLAN Commands
COMMAND DESCRIPTION
show arp inspection vlan <vlan-
list>
Displays ARP inspection settings for the specified VLAN(s).
arp inspection vlan <vlan-list>
Enables ARP inspection on the specified VLAN(s).
no arp inspection vlan <vlan-
list>
Disables ARP inspection on the specified VLAN(s).
arp inspection vlan <vlan-list>
logging [all|none|permit|deny]
Enables logging of ARP inspection events on the specified
VLAN(s). Optionally specifies which types of events to log.
no arp inspection vlan <vlan-
list> logging
Disables logging of messages generated by ARP inspection for
the specified VLAN(s).
OLT2412# show arp inspection filter
Filtering aging timeout : 300
MacAddress VLAN Port Expiry (sec) Reason
----------------- ---- ----- ------------ --------------
Total number of bindings: 0
Table 103 show arp inspection filter
LABEL DESCRIPTION
Filtering aging timeout This field displays how long the MAC address filters remain in the OLT after the OLT
identifies an unauthorized ARP packet. The OLT automatically deletes the MAC
address filter afterwards.
MacAddress This field displays the source MAC address in the MAC address filter.
VLAN This field displays the source VLAN ID in the MAC address filter.
Port This field displays the source port of the discarded ARP packet.
Expiry (sec) This field displays how long (in seconds) the MAC address filter remains in the OLT.
You can also delete the record manually (Delete).
Reason This field displays the reason the ARP packet was discarded.
MAC+VLAN: The MAC address and VLAN ID were not in the binding table.
IP: The MAC address and VLAN ID were in the binding table, but the IP address
was not valid.
Port: The MAC address, VLAN ID, and IP address were in the binding table, but the
port number was not valid.

Содержание