ip arp inspection
Настравиваю IPMB, задача проверять только ip не учитывая мак:
ip source binding "3" 10.203.1.117 00:00:00:00:00:00 vlan 10 interface gigabitEthernet 1/0/3 both
ip source binding "5" 10.203.1.119 00:00:00:00:00:00 vlan 10 interface gigabitEthernet 1/0/5 both
ip verify source logging
ip arp inspection
ip arp inspection validate ip
ip arp inspection vlan 10
ip arp inspection vlan 10 logging
Клиент:
interface gigabitEthernet 1/0/3
switchport general allowed vlan 10 untagged
switchport pvid 10
mac address-table max-mac-count max-number 10 exceed-max-learned enable
storm-control broadcast 64
storm-control multicast 64
storm-control unicast 64
ip dhcp filter
ip dhcp filter limit rate 5
ip dhcp filter decline rate 5
ip verify source sip
ip arp inspection limit-rate 10
ip arp inspection burst-interval 5
no lldp receive
no lldp transmit
ip dhcp relay information option
ip dhcp relay information strategy replace
loopback-detection config process-mode vlan-based recovery-mode auto
ipv6 dhcp snooping max-entries 10
ipv6 nd snooping max-entries 10
ipv6 dhcp filter
ipv6 dhcp filter limit rate 10
ipv6 dhcp filter decline rate 10
#
Аплинк:
interface gigabitEthernet 1/0/25
switchport general allowed vlan 10,500-501 tagged
switchport acceptable frame tagged
qos trust mode dot1p
ip arp inspection trust
no ipv6 mld snooping
ethernet-oam
#
Как итог:
#2022-11-28 15:47:04,[ARP&IP Defend]/3/Dropped ARP request PKT SMAC d8:cb:8a:cf:87:38 DMAC ff:ff:ff:ff:ff:ff SDMAC d8:cb:8a:cf:87:38 SDIP 10.203.1.117 TMAC 00:00:00:00:00:00 TIP 10.203.0.1 on Gi1/0/3 in vlan 10, due to - IMPB MATCH FAILURE.
#2022-11-28 15:46:34,[ARP&IP Defend]/3/Dropped ARP request PKT SMAC d8:cb:8a:cf:87:38 DMAC ff:ff:ff:ff:ff:ff SDMAC d8:cb:8a:cf:87:38 SDIP 10.203.1.117 TMAC 00:00:00:00:00:00 TIP 10.203.0.1 on Gi1/0/3 in vlan 10, due to - IMPB MATCH FAILURE.
#2022-11-28 15:46:04,[ARP&IP Defend]/3/Dropped ARP reply PKT SMAC d8:cb:8a:cf:87:38 DMAC 28:8a:1c:09:26:41 SDMAC d8:cb:8a:cf:87:38 SDIP 10.203.1.117 TMAC 28:8a:1c:09:26:41 TIP 10.203.0.1 on Gi1/0/3 in vlan 10, due to - IMPB MATCH FAILURE.
Если выключить ip arp inspection, то начинает рабоать.
Как поправить данное поведение?