DAI inspection - Rate limit

Unanswered Question
Apr 8th, 2010

Hey All,


I've implemented layer 2 security for DAI and DHCP snooping etc


I've set the the following interface command for packets per second.


"ip arp inspection limit rate 100"


But I noticed printers go over the 100 now and then, and the port goes into err-disable.


So questions,


Is 100 a appropriate value? I've never had any user ports have issues as of yet.

Is there a way to make limit rate unlimited for specified mac addresses? as the printers can move around.


Many Thanks,


Alan

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
alanc3141592654 Thu, 04/08/2010 - 20:34

thanks, i've already read through the guide and know the default values.

Raising to a larger value, does make it work. But I was just wondering if there is a way to set up a access list or something, so it still works when the printer moves to a new port..?


i.e there is a arp access-list for devices with static IPs.


Maybe this is not possible.


A

Actions

This Discussion