H3C S6800 Switch Series

Similar documents
H3C S6800 Switch Series

HPE FlexNetwork 5510 HI Switch Series

HPE 5920 & 5900 Switch Series

HPE FlexNetwork 5510 HI Switch Series

H3C S5130-HI Switch Series

HPE FlexFabric 7900 Switch Series

H3C S6520XE-HI Switch Series

HP FlexFabric 5930 Switch Series

HPE FlexFabric 5940 Switch Series

H3C S9800 Switch Series

H3C S7500E-XS Switch Series

H3C S7500E-XS Switch Series

H3C S3100V2-52TP Switch

H3C S5560S-EI & S5130S-HI[EI] & S5110V2 & S3100V3-EI Switch Series

H3C S6300 Switch Series

H3C S3100V2 Switch Series

H3C S12500-X & S12500X-AF Switch Series

H3C S12500 Series Routing Switches

H3C S5500-HI Switch Series

H3C S5130-HI Switch Series

H3C S5120-HI Switch Series

H3C S5500-HI Switch Series

HPE FlexNetwork MSR Router Series

H3C S5120-EI Switch Series

HP 3600 v2 Switch Series

H3C SR6600 Routers. Layer 3 IP Services. Command Reference. Hangzhou H3C Technologies Co., Ltd.

H3C S5130-EI Switch Series

H3C S10500 Switch Series

HP 5920 & 5900 Switch Series

H3C S3600V2 Switch Series

H3C S9800 Switch Series

H3C S6800 Switch Series

H3C S5120-EI Switch Series

HP FlexFabric 5930 Switch Series

HP 6125 Blade Switch Series

H3C MSR Router Series

H3C SR6600/SR6600-X Routers

H3C S7500E Switch Series

HP A5830 Switch Series Layer 3 - IP Services. Configuration Guide. Abstract

H3C SecPath Series High-End Firewalls

H3C S7500E Switch Series

H3C S6520XE-HI Switch Series

HPE FlexFabric 5950 Switch Series

H3C S6520XE-HI Switch Series

H3C S5120-SI Switch Series

HP 5120 SI Switch Series

Configuring IPv6 basics

H3C SecPath Series Firewalls and UTM Devices

H3C S6520XE-HI Switch Series

H3C SecPath Series Firewalls and UTM Devices

HP FlexFabric 5700 Switch Series

H3C S5120-EI Switch Series

H3C S5130-EI Switch Series

HP A3100 v2 Switch Series

Command Manual Network Protocol. Table of Contents

H3C SecPath Series High-End Firewalls

H3C Firewall Devices. High Availability Configuration Guide (Comware V7) Hangzhou H3C Technologies Co., Ltd.

H3C S5830V2 & S5820V2 Switch Series

HP 5120 EI Switch Series

HP A5120 EI Switch Series IRF. Command Reference. Abstract

HP MSR Router Series. IPX Configuration Guide(V5) Part number: Software version: CMW520-R2513 Document version: 6PW

Operation Manual IPv6 H3C S3610&S5510 Series Ethernet Switches Table of Contents. Table of Contents

tcp ipv6 timer fin-timeout 40 tcp ipv6 timer syn-timeout 40 tcp ipv6 window 41

Table of Contents 1 IPv6 Configuration IPv6 Application Configuration 2-1

H3C S7500E-X Switch Series

H3C SecPath Series High-End Firewalls

H3C S5120-EI Series Ethernet Switches. Layer 3 - IP Services. Configuration Guide. Hangzhou H3C Technologies Co., Ltd.

HP 5130 EI Switch Series

Table of Contents 1 IPv6 Basics Configuration 1-1

H3C SecPath Series High-End Firewalls

HP 5920 & 5900 Switch Series

About the HP 830 Series PoE+ Unified Wired-WLAN Switch and HP 10500/ G Unified Wired-WLAN Module

IPv6 Neighbor Discovery

H3C S6300 Switch Series

H3C S3100V2-52TP Switch

HP 5820X & 5800 Switch Series IRF. Command Reference. Abstract

H3C S5830V2 & S5820V2 Switch Series

HP 5920 & 5900 Switch Series

H3C S5120-HI Switch Series

HP High-End Firewalls

H3C S5120-SI Switch Series

Table of Contents 1 IPv6 Configuration IPv6 Application Configuration 2-1

About the Configuration Guides for HP Unified

Table of Contents 1 IPv6 Configuration IPv6 Application Configuration 2-1

IPv6 Neighbor Discovery

Troubleshooting DHCP server configuration 28

H3C S9500E Series Routing Switches

H3C S6800 Switch Series

H3C SecBlade SSL VPN Card

IPv6 Neighbor Discovery

Layer 3 - IP Routing Command Reference

H3C S9500 Series Routing Switches

H3C S5130-HI Switch Series

IPv6 Neighbor Discovery

IPv6 Neighbor Discovery

HP 10500/ G Unified Wired-WLAN Module

Operation Manual ARP H3C S5500-SI Series Ethernet Switches. Table of Contents

DHCP and DDNS Services

DHCP Overview. Introduction to DHCP

H3C S9800 Switch Series

Transcription:

H3C S6800 Switch Series Layer 3 IP Services Command Reference New H3C Technologies Co., Ltd. http://www.h3c.com Software version: Release 2609 and later Document version: 6W103-20190104

Copyright 2019, New H3C Technologies Co., Ltd. and its licensors All rights reserved No part of this manual may be reproduced or transmitted in any form or by any means without prior written consent of New H3C Technologies Co., Ltd. Trademarks Except for the trademarks of New H3C Technologies Co., Ltd., any trademarks that may be mentioned in this document are the property of their respective owners. Notice The information in this document is subject to change without notice. All contents in this document, including statements, information, and recommendations, are believed to be accurate, but they are presented without warranty of any kind, express or implied. H3C shall not be liable for technical or editorial errors or omissions contained herein.

Preface This command reference describes IP services commands. This preface includes the following topics about the documentation: Audience. Conventions. Documentation feedback. Audience This documentation is intended for: Network planners. Field technical support and servicing engineers. Network administrators working with the S6800 switch series. Conventions The following information describes the conventions used in the documentation. Command conventions Convention Boldface Italic Description Bold text represents commands and keywords that you enter literally as shown. Italic text represents arguments that you replace with actual values. [ ] Square brackets enclose syntax choices (keywords or arguments) that are optional. { x y... } [ x y... ] { x y... } * [ x y... ] * &<1-n> Braces enclose a set of required syntax choices separated by vertical bars, from which you select one. Square brackets enclose a set of optional syntax choices separated by vertical bars, from which you select one or none. Asterisk marked braces enclose a set of required syntax choices separated by vertical bars, from which you select a minimum of one. Asterisk marked square brackets enclose optional syntax choices separated by vertical bars, from which you select one choice, multiple choices, or none. The argument or keyword and argument combination before the ampersand (&) sign can be entered 1 to n times. # A line that starts with a pound (#) sign is comments. GUI conventions Convention Boldface > Description Window names, button names, field names, and menu items are in Boldface. For example, the New User window opens; click OK. Multi-level menus are separated by angle brackets. For example, File > Create > Folder.

Symbols Convention WARNING! CAUTION: IMPORTANT: NOTE: TIP: Description An alert that calls attention to important information that if not understood or followed can result in personal injury. An alert that calls attention to important information that if not understood or followed can result in data loss, data corruption, or damage to hardware or software. An alert that calls attention to essential information. An alert that contains additional or supplementary information. An alert that provides helpful information. Network topology icons Convention Description Represents a generic network device, such as a router, switch, or firewall. Represents a routing-capable device, such as a router or Layer 3 switch. Represents a generic switch, such as a Layer 2 or Layer 3 switch, or a router that supports Layer 2 forwarding and other Layer 2 features. Represents an access controller, a unified wired-wlan module, or the access controller engine on a unified wired-wlan switch. Represents an access point. T Represents a wireless terminator unit. T Represents a wireless terminator. Represents a mesh access point. Represents omnidirectional signals. Represents directional signals. Represents a security product, such as a firewall, UTM, multiservice security gateway, or load balancing device. Represents a security module, such as a firewall, load balancing, NetStream, SSL VPN, IPS, or ACG module. provided in this document in this document might use devices that differ from your device in hardware model, configuration, or software version. It is normal that the port numbers, sample output, screenshots, and other information in the examples differ from what you have on your device.

Documentation feedback You can e-mail your comments about product documentation to info@h3c.com. We appreciate your comments.

Contents ARP commands 1 arp check enable 1 arp check log enable 1 arp max-learning-num 2 arp max-learning-number 3 arp mode uni 4 arp multiport 5 arp smooth 5 arp static 6 arp timer aging 8 display arp 8 display arp entry-limit 11 display arp ip-address 12 display arp openflow count 12 display arp timer aging 13 display arp vpn-instance 13 reset arp 14 Gratuitous ARP commands 15 arp ip-conflict log prompt 15 arp send-gratuitous-arp 15 gratuitous-arp mac-change retransmit 16 gratuitous-arp-learning enable 17 gratuitous-arp-sending enable 18 Proxy ARP commands 19 display local-proxy-arp 19 display proxy-arp 19 local-proxy-arp enable 20 proxy-arp enable 21 ARP snooping commands 23 arp snooping enable 23 display arp snooping 23 reset arp snooping 24 ARP fast-reply commands 26 arp fast-reply enable 26 ARP direct route advertisement commands 27 arp route-direct advertise 27 IP addressing commands 28 display ip interface 28 display ip interface brief 30 ip address 32 ip address unnumbered 33 DHCP commands 35 Common DHCP commands 35 dhcp client-detect 35 dhcp dscp 35 dhcp enable 36 dhcp flood-protection aging-time 36 dhcp flood-protection enable 37 dhcp flood-protection threshold 38 dhcp log enable 39 i

dhcp select 39 DHCP server commands 40 address range 40 bims-server 41 bootfile-name 42 class ip-pool 43 class option-group 43 class range 44 default ip-pool 45 dhcp apply-policy 46 dhcp class 47 dhcp option-group 47 dhcp policy 48 dhcp server always-broadcast 49 dhcp server apply ip-pool 49 dhcp server bootp ignore 50 dhcp server bootp reply-rfc-1048 51 dhcp server check mac-address 51 dhcp server database filename 52 dhcp server database update interval 53 dhcp server database update now 54 dhcp server database update stop 55 dhcp server forbidden-ip 55 dhcp server ip-pool 56 dhcp server ping packets 57 dhcp server ping timeout 57 dhcp server relay information enable 58 display dhcp server conflict 59 display dhcp server database 60 display dhcp server expired 60 display dhcp server free-ip 61 display dhcp server ip-in-use 62 display dhcp server pool 64 display dhcp server statistics 66 dns-list 68 domain-name 69 expired 69 forbidden-ip 70 gateway-list 71 if-match 72 ip-in-use threshold 74 nbns-list 75 netbios-type 75 network 76 next-server 77 option 78 reset dhcp server conflict 79 reset dhcp server expired 80 reset dhcp server ip-in-use 80 reset dhcp server statistics 81 static-bind 81 tftp-server domain-name 83 tftp-server ip-address 83 valid class 84 verify class 85 voice-config 85 vpn-instance 86 DHCP relay agent commands 87 dhcp relay check mac-address 87 dhcp relay check mac-address aging-time 88 dhcp relay client-information record 88 dhcp relay client-information refresh 89 ii

dhcp relay client-information refresh enable 90 dhcp relay dhcp-server timeout 90 dhcp relay gateway 91 dhcp relay information circuit-id 92 dhcp relay information enable 94 dhcp relay information remote-id 94 dhcp relay information strategy 95 dhcp relay mac-forward enable 96 dhcp relay master-server switch-delay 97 dhcp relay release ip 98 dhcp relay request-from-tunnel discard 98 dhcp relay server-address 99 dhcp relay server-address algorithm 100 dhcp relay source-address 101 dhcp smart-relay enable 102 dhcp-server timeout 102 display dhcp relay check mac-address 103 display dhcp relay client-information 104 display dhcp relay information 105 display dhcp relay server-address 106 display dhcp relay statistics 107 gateway-list 108 master-server switch-delay 109 remote-server 110 remote-server algorithm 110 reset dhcp relay client-information 111 reset dhcp relay statistics 112 DHCP client commands 112 dhcp client dad enable 112 dhcp client dscp 113 dhcp client identifier 113 display dhcp client 114 ip address dhcp-alloc 117 DHCP snooping commands 117 dhcp snooping binding database filename 117 dhcp snooping binding database update interval 119 dhcp snooping binding database update now 120 dhcp snooping binding record 120 dhcp snooping check mac-address 121 dhcp snooping check request-message 122 dhcp snooping deny 122 dhcp snooping disable 123 dhcp snooping enable 123 dhcp snooping enable vlan 124 dhcp snooping information circuit-id 125 dhcp snooping information enable 126 dhcp snooping information remote-id 127 dhcp snooping information strategy 128 dhcp snooping log enable 129 dhcp snooping max-learning-num 130 dhcp snooping rate-limit 130 dhcp snooping trust 131 dhcp snooping trust interface 132 dhcp snooping trust tunnel 133 display dhcp snooping binding 133 display dhcp snooping binding database 135 display dhcp snooping information 135 display dhcp snooping packet statistics 137 display dhcp snooping trust 137 reset dhcp snooping binding 138 reset dhcp snooping packet statistics 138 BOOTP client commands 139 iii

display bootp client 139 ip address bootp-alloc 140 DNS commands 141 display dns domain 141 display dns host 142 display dns server 143 display ipv6 dns server 144 dns domain 145 dns dscp 145 dns proxy enable 146 dns server 147 dns source-interface 147 dns spoofing 148 dns trust-interface 149 ip host 150 ipv6 dns dscp 151 ipv6 dns server 151 ipv6 dns spoofing 152 ipv6 host 153 reset dns host 154 DDNS commands 155 ddns apply policy 155 ddns dscp 155 ddns policy 156 display ddns policy 157 interval 158 method 159 password 160 ssl-client-policy 161 url 161 username 163 Basic IP forwarding commands 165 display fib 165 forwarding split-horizon 166 ip forwarding-table save 167 Load sharing commands 168 display ip load-sharing mode 168 display ip load-sharing path 169 ip load-sharing local-first enable 170 ip load-sharing mode 171 ip load-sharing symmetric enable 172 Fast forwarding commands 173 display ip fast-forwarding aging-time 173 display ip fast-forwarding cache 173 display ip fast-forwarding fragcache 174 ip fast-forwarding aging-time 175 ip fast-forwarding load-sharing 176 reset ip fast-forwarding cache 176 IPv4 adjacency table commands 178 display adjacent-table 178 IPv6 adjacency table commands 180 display ipv6 adjacent-table 180 IRDP commands 182 ip irdp 182 iv

ip irdp address 182 ip irdp interval 183 ip irdp lifetime 184 ip irdp multicast 184 ip irdp preference 185 IP performance optimization commands 186 display icmp statistics 186 display ip statistics 186 display rawip 188 display rawip verbose 188 display tcp 191 display tcp statistics 192 display tcp verbose 194 display udp 198 display udp statistics 199 display udp verbose 199 ip forward-broadcast 202 ip icmp error-interval 203 ip icmp fragment discarding 204 ip icmp source 205 ip mtu 205 ip reassemble local enable 206 ip redirects enable 207 ip ttl-expires enable 207 ip unreachables enable 208 reset ip statistics 209 reset tcp statistics 209 reset udp statistics 210 tcp mss 210 tcp path-mtu-discovery 211 tcp syn-cookie enable 212 tcp timer fin-timeout 212 tcp timer syn-timeout 213 tcp window 214 UDP helper commands 215 display udp-helper interface 215 reset udp-helper statistics 215 udp-helper broadcast-map 216 udp-helper enable 217 udp-helper port 217 udp-helper server 218 IPv6 basics commands 220 display ipv6 fib 220 display ipv6 icmp statistics 221 display ipv6 interface 222 display ipv6 interface prefix 226 display ipv6 nd snooping 227 display ipv6 nd snooping count 228 display ipv6 neighbors 229 display ipv6 neighbors count 231 display ipv6 neighbors entry-limit 231 display ipv6 neighbors vpn-instance 232 display ipv6 pathmtu 233 display ipv6 prefix 234 display ipv6 rawip 235 display ipv6 rawip verbose 236 display ipv6 statistics 239 display ipv6 tcp 240 display ipv6 tcp verbose 241 v

display ipv6 udp 244 display ipv6 udp verbose 245 ipv6 address 248 ipv6 address anycast 249 ipv6 address auto 249 ipv6 address auto link-local 250 ipv6 address eui-64 251 ipv6 address link-local 252 ipv6 address prefix-number 253 ipv6 extension-header drop enable 254 ipv6 hop-limit 254 ipv6 hoplimit-expires enable 255 ipv6 icmpv6 error-interval 255 ipv6 icmpv6 multicast-echo-reply enable 256 ipv6 icmpv6 source 257 ipv6 mtu 257 ipv6 nd autoconfig managed-address-flag 258 ipv6 nd autoconfig other-flag 259 ipv6 nd dad attempts 259 ipv6 nd ns retrans-timer 260 ipv6 nd nud reachable-time 261 ipv6 nd ra halt 262 ipv6 nd ra hop-limit unspecified 262 ipv6 nd ra interval 263 ipv6 nd ra no-advlinkmtu 263 ipv6 nd ra prefix 264 ipv6 nd ra prefix default 265 ipv6 nd ra router-lifetime 266 ipv6 nd router-preference 267 ipv6 nd snooping dad retrans-timer 267 ipv6 nd snooping enable global 268 ipv6 nd snooping enable link-local 269 ipv6 nd snooping glean source 269 ipv6 nd snooping lifetime 270 ipv6 nd snooping max-learning-num 270 ipv6 nd snooping uplink 271 ipv6 neighbor 271 ipv6 neighbor link-local minimize 273 ipv6 neighbor stale-aging 273 ipv6 neighbors max-learning-num 274 ipv6 pathmtu 275 ipv6 pathmtu age 275 ipv6 prefer temporary-address 276 ipv6 prefix 277 ipv6 reassemble local enable 278 ipv6 redirects enable 278 ipv6 temporary-address 279 ipv6 unreachables enable 280 local-proxy-nd enable 281 proxy-nd enable 281 reset ipv6 nd snooping 282 reset ipv6 neighbors 282 reset ipv6 pathmtu 283 reset ipv6 statistics 283 DHCPv6 commands 285 Common DHCPv6 commands 285 display ipv6 dhcp duid 285 ipv6 dhcp advertise pd-route 285 ipv6 dhcp dscp 286 ipv6 dhcp log enable 286 ipv6 dhcp select 287 vi

DHCPv6 server commands 288 address range 288 class pool 289 default pool 290 display ipv6 dhcp option-group 290 display ipv6 dhcp pool 292 display ipv6 dhcp prefix-pool 295 display ipv6 dhcp server 296 display ipv6 dhcp server conflict 297 display ipv6 dhcp server database 298 display ipv6 dhcp server expired 299 display ipv6 dhcp server ip-in-use 300 display ipv6 dhcp server pd-in-use 302 display ipv6 dhcp server statistics 304 dns-server 305 domain-name 306 if-match 307 ipv6 dhcp apply-policy 309 ipv6 dhcp class 309 ipv6 dhcp option-group 310 ipv6 dhcp policy 311 ipv6 dhcp pool 311 ipv6 dhcp prefix-pool 312 ipv6 dhcp server 313 ipv6 dhcp server apply pool 314 ipv6 dhcp server database filename 315 ipv6 dhcp server database update interval 317 ipv6 dhcp server database update now 317 ipv6 dhcp server database update stop 318 ipv6 dhcp server forbidden-address 319 ipv6 dhcp server forbidden-prefix 320 network 321 option 322 option-group 323 prefix-pool 324 reset ipv6 dhcp server conflict 325 reset ipv6 dhcp server expired 325 reset ipv6 dhcp server ip-in-use 326 reset ipv6 dhcp server pd-in-use 327 reset ipv6 dhcp server statistics 327 sip-server 328 static-bind 329 temporary address range 330 vpn-instance 331 DHCPv6 relay agent commands 331 display ipv6 dhcp relay client-information address 331 display ipv6 dhcp relay client-information pd 333 display ipv6 dhcp relay server-address 335 display ipv6 dhcp relay statistics 336 gateway-list 338 ipv6 dhcp client-detect 339 ipv6 dhcp relay client-information record 339 ipv6 dhcp relay client-link-address enable 340 ipv6 dhcp relay gateway 341 ipv6 dhcp relay interface-id 341 ipv6 dhcp relay release-agent 342 ipv6 dhcp relay server-address 343 ipv6 dhcp relay source-address 344 remote-server 345 reset ipv6 dhcp relay client-information address 346 reset ipv6 dhcp relay client-information pd 346 reset ipv6 dhcp relay statistics 347 vii

DHCPv6 client commands 347 display ipv6 dhcp client 347 display ipv6 dhcp client statistics 350 ipv6 address dhcp-alloc 351 ipv6 dhcp client dscp 352 ipv6 dhcp client duid 352 ipv6 dhcp client pd 353 ipv6 dhcp client stateful 354 ipv6 dhcp client stateless enable 355 reset ipv6 dhcp client statistics 356 DHCPv6 snooping commands 356 display ipv6 dhcp snooping binding 356 display ipv6 dhcp snooping binding database 357 display ipv6 dhcp snooping packet statistics 358 display ipv6 dhcp snooping pd binding 359 display ipv6 dhcp snooping trust 360 ipv6 dhcp snooping binding database filename 360 ipv6 dhcp snooping binding database update interval 362 ipv6 dhcp snooping binding database update now 362 ipv6 dhcp snooping binding record 363 ipv6 dhcp snooping check request-message 363 ipv6 dhcp snooping deny 364 ipv6 dhcp snooping enable 365 ipv6 dhcp snooping log enable 365 ipv6 dhcp snooping max-learning-num 366 ipv6 dhcp snooping option interface-id enable 367 ipv6 dhcp snooping option interface-id string 367 ipv6 dhcp snooping option remote-id enable 368 ipv6 dhcp snooping option remote-id string 369 ipv6 dhcp snooping pd binding record 370 ipv6 dhcp snooping rate-limit 370 ipv6 dhcp snooping trust 371 reset ipv6 dhcp snooping binding 372 reset ipv6 dhcp snooping packet statistics 372 reset ipv6 dhcp snooping pd binding 373 IPv6 fast forwarding commands 374 display ipv6 fast-forwarding aging-time 374 display ipv6 fast-forwarding cache 374 ipv6 fast-forwarding aging-time 375 ipv6 fast-forwarding load-sharing 376 reset ipv6 fast-forwarding cache 377 Tunneling commands 378 bandwidth 378 default 378 description 379 destination 379 display interface tunnel 380 interface tunnel 384 mtu 385 reset counters interface tunnel 386 service 386 shutdown 387 source 388 tunnel dfbit enable 389 tunnel discard ipv4-compatible-packet 389 tunnel log updown with-tag 390 tunnel tos 390 tunnel ttl 391 tunnel vpn-instance 392 viii

GRE commands 394 keepalive 394 HTTP redirect commands 395 http-redirect https-port 395 http-redirect ssl-server-policy 395 Index 397 ix

ARP commands arp check enable Use arp check enable to enable dynamic ARP entry check. Use undo arp check enable to disable dynamic ARP entry check. arp check enable undo arp check enable Dynamic ARP entry check is enabled. System view Dynamic ARP entry check disables a device from supporting dynamic ARP entries with multicast MAC addresses. The device cannot learn dynamic ARP entries containing multicast MAC addresses. You cannot manually add static ARP entries that contain multicast MAC addresses. When dynamic ARP entry check is disabled, ARP entries containing multicast MAC addresses are supported. The device can learn dynamic ARP entries containing multicast MAC addresses obtained from the ARP packets sourced from a unicast MAC address. You can also manually add static ARP entries containing multicast MAC addresses. # Enable dynamic ARP entry check. [Sysname] arp check enable arp check log enable Use arp check log enable to enable the ARP logging feature. Use undo arp check log enable to disable the ARP logging feature. arp check log enable undo arp check log enable ARP logging is disabled. System view 1

This feature enables a device to log ARP events when ARP cannot resolve IP addresses correctly. The device can log the following ARP events: On a proxy ARP-disabled interface, the target IP address of a received ARP packet is not one of the following IP addresses: The IP address of the receiving interface. The virtual IP address of the VRRP group. The sender IP address of a received ARP reply conflicts with one of the following IP addresses: The IP address of the receiving interface. The virtual IP address of the VRRP group. The device sends ARP log messages to the information center. You can use the info-center source command to specify the log output rules for the information center. For more information about information center, see Network Management and Monitoring Configuration Guide. The device can generate a large number of ARP logs. To conserve system resources, enable ARP logging only when you are auditing or troubleshooting ARP events. # Enable ARP logging. [Sysname] arp check log enable arp max-learning-num Use arp max-learning-num to set the maximum number of dynamic ARP entries that an interface can learn. Use undo arp max-learning-num to restore the default. arp max-learning-num max-number [ alarm alarm-threshold ] undo arp max-learning-num The maximum number of dynamic ARP entries that an interface can learn depends on the ARP table capacity set by using the hardware-resource switch-mode command. For information about the hardware-resource switch-mode command, see Fundamentals Command Reference. Layer 2 Ethernet interface view Layer 2 aggregate interface view Layer 3 Ethernet interface view Layer 3 Ethernet subinterface view Layer 3 aggregate interface view Layer 3 aggregate subinterface view VXLAN VSI interface view VLAN interface view 2

max-number: Specifies the maximum number of dynamic ARP entries for an interface. The value range for this argument is 0 to N. The value for N depends on the ARP table capacity. alarm alarm-threshold: Specifies an alarm threshold for dynamic ARP learning, in percentage. The value range for the alarm-threshold argument is 1 to 100. The device generates a log message when the number of dynamic ARP entries learned on an interface reaches the value calculated by using the formula: (max-number alarm-threshold)/100. If you do not specify the alarm threshold, the device does not generate log messages. An interface can dynamically learn ARP entries. To prevent an interface from holding too many ARP entries, you can set the maximum number of dynamic ARP entries that the interface can learn. When the maximum number is reached, the interface stops learning ARP entries. When the number argument is set to 0, the interface is disabled from learning dynamic ARP entries. # Specify VLAN-interface 40 to learn a maximum of 10 dynamic ARP entries. [Sysname] interface vlan-interface 40 [Sysname-Vlan-interface40] arp max-learning-num 10 # Specify Ten-GigabitEthernet 1/0/1 to learn a maximum of 10 dynamic ARP entries. [Sysname] interface ten-gigabitethernet 1/0/1 [Sysname-Ten-GigabitEthernet1/0/1] arp max-learning-num 10 # Specify Layer 2 aggregate interface Bridge-Aggregation 1 to learn a maximum of 10 dynamic ARP entries. [Sysname] interface bridge-aggregation 1 [Sysname-Bridge-Aggregation1] arp max-learning-num 10 # Specify Layer 3 aggregate interface Route-Aggregation 1 to learn a maximum of 10 dynamic ARP entries. [Sysname] interface route-aggregation 1 [Sysname-Route-Aggregation1] arp max-learning-num 10 arp max-learning-number Use arp max-learning-number to set the maximum number of dynamic ARP entries that a device can learn. Use undo arp max-learning-number to restore the default. arp max-learning-number max-number slot slot-number undo arp max-learning-number slot slot-number The maximum number of dynamic ARP entries that a device can learn depends on the ARP table capacity set by using the hardware-resource switch-mode command. For information about the hardware-resource switch-mode command, see Fundamentals Command Reference. 3

System view max-number: Specifies the maximum number of dynamic ARP entries for a device. The value range for this argument is 0 to N. The value for N depends on the ARP table capacity. slot slot-number: Specifies an IRF member device by its member ID. A device can dynamically learn ARP entries. To prevent a device from holding too many ARP entries, you can set the maximum number of dynamic ARP entries that the device can learn. When the maximum number is reached, the device stops learning ARP entries. When the number argument is set to 0, the device is disabled from learning dynamic ARP entries. # Configure the device to learn a maximum of 64 dynamic ARP entries. [Sysname] arp max-learning-number 64 slot 1 arp mode uni Use arp mode uni to configure a port as a customer-side port. Use undo arp mode to restore the default. arp mode uni undo arp mode A port operates as a network-side port. VLAN interface view VXLAN VSI interface view By default, the device associates an ARP entry with routing information when the device learns an ARP entry. The ARP entry provides the next hop information for routing. To save hardware resources, you can use this command to specify a port that connects to a user terminal as a customer-side port. The device will not associate the routing information with the learned ARP entries. # Configure VLAN-interface 2 as a customer-side port. [Sysname] interface vlan-interface 2 [Sysname-Vlan-interface2] arp mode uni 4

arp multiport Use arp multiport to configure a multiport ARP entry. Use undo arp to delete an ARP entry. arp multiport ip-address mac-address vlan-id [ vpn-instance vpn-instance-name ] undo arp ip-address [ vpn-instance-name ] No multiport ARP entries exist. System view ip-address: Specifies an IP address for the multiport ARP entry. mac-address: Specifies a MAC address for the multiport ARP entry, in the format of H-H-H. vlan-id: Specifies a VLAN for the multiport ARP entry, in the range of 1 to 4094. The specified VLAN must already exist. vpn-instance vpn-instance-name: Specifies an MPLS L3VPN instance to which the multiport ARP entry belongs. The vpn-instance-name argument represents the VPN instance name, a case-sensitive string of 1 to 31 characters. The specified VPN instance must already exist. To specify a multiport ARP entry on the public network, do not specify this option. If the VLAN or the corresponding VLAN interface is deleted, the multiport ARP entry is also deleted. To make the multiport ARP entry effective for packet forwarding, you must configure a multicast or multiport unicast MAC address entry to specify multiple output interfaces. The MAC address entry must have the same MAC address and VLAN ID as the multiport ARP entry. In addition, the IP address in the multiport ARP entry must reside on the same subnet as the VLAN interface of the specified VLAN. # Configure a multiport ARP entry that contains IP address 202.38.10.2 and MAC address 00e0-fc01-0000 in VLAN 10. [Sysname] arp multiport 202.38.10.2 00e0-fc01-0000 10 display arp multiport reset arp multiport arp smooth Use arp smooth to synchronize ARP entries from the master device to all subordinate devices. arp smooth 5

User view arp static # Synchronize ARP entries from the master device to all subordinate devices. <Sysname> arp smooth Use arp static to configure a static ARP entry. Use undo arp to delete an ARP entry. arp static ip-address mac-address [ vlan-id interface-type interface-number vsi-interface vsi-interface-id tunnel number vsi vsi-name vsi-interface vsi-interface-id interface-type interface-number service-instance instance-id vsi vsi-name ] [ vpn-instance vpn-instance-name ] undo arp ip-address [ vpn-instance-name ] No static ARP entries exist. System view ip-address: Specifies an IP address for the static ARP entry. mac-address: Specifies a MAC address for the static ARP entry, in the format of H-H-H. vlan-id: Specifies the ID of a VLAN to which the static ARP entry belongs. The value range is 1 to 4094. interface-type interface-number: Specifies an interface by its type and number. vsi-interface vsi-interface-id: Specifies a VSI interface by its number. tunnel number: Specifies a tunnel interface by its number in the range of 0 to 1. service-instance instance-id: Specifies an Ethernet service instance by its ID in the range of 1 to 4096. You must specify this option if you specify a Layer 2 Ethernet interface for the preceding interface-type interface-number arguments. Do not specify this option if you specify an interface of other types for the preceding interface-type interface-number argument. vsi vsi-name: Specifies a VSI by its name, a case-sensitive string of 1 to 31 characters. vpn-instance vpn-instance-name: Specifies an MPLS L3VPN instance to which the static ARP entry belongs. The vpn-instance-name argument represents the VPN instance name, a case-sensitive string of 1 to 31 characters. The VPN instance must already exist. To specify a static ARP entry on the public network, do not specify this option. A static ARP entry is manually configured and maintained. It does not age out and cannot be overwritten by any dynamic ARP entry. 6

Static ARP entries can be short or long. A resolved short static ARP entry becomes unresolved upon certain events, for example, when the resolved output interface goes down, or the corresponding VLAN or VLAN interface is deleted. Long static ARP entries are effective or ineffective. Ineffective long static ARP entries cannot be used for packet forwarding. A long static ARP entry is ineffective when any of the following conditions exists: The corresponding VLAN interface or output interface is down. The IP address in the entry conflicts with a local IP address. No local interface has an IP address in the same subnet as the IP address in the ARP entry. If you specify the vlan-id interface-type interface-number argument, follow these restrictions and guidelines: The interface can be an Ethernet interface or an aggregate interface. The VLAN and VLAN interface must already exist. The specified Ethernet interface must belong to the specified VLAN. The IP address of the VLAN interface and the IP address specified by the ip-address argument must be on the same network. A long static ARP entry in a VLAN is deleted if the VLAN or VLAN interface is deleted. On a VXLAN IP gateway that forwards traffic among VXLANs through VXLAN tunnels, a VSI interface can act as the gateway for multiple VXLANs. The VSI interface (input interface) might be connected to multiple VXLAN tunnel interfaces (output interfaces). In this case, you must specify the vsi-interface vsi-interface-id tunnel number vsi vsi-name parameters to identify a VSI interface-vsi-vxlan tunnel interface binding. For more information about VSI interfaces, VSI, and VXLAN tunnel interfaces, see VXLAN Configuration Guide. On a VXLAN IP gateway that forwards traffic from multiple local sites to remote sites, a VSI interface can act as the gateway for multiple local sites. The VSI interface (input interface) might be associated with multiple Ethernet services (output interfaces) on Layer 2 Ethernet interfaces through which the VSI interface connects to the local sites. In this case, you must specify the vsi-interface vsi-interface-id interface-type interface-number service-instance instance-id vsi vsi-name parameters to identify a VSI interface-layer 2 Ethernet interface-ethernet service instance-vsi binding. For more information about VSI interfaces, VSI, and Ethernet service instances, see VXLAN Configuration Guide. # Configure a long static ARP entry that contains IP address 202.38.10.2, MAC address 00e0-fc01-0000, and output interface Ten-GigabitEthernet 1/0/1 in VLAN 10. [Sysname] arp static 202.38.10.2 00e0-fc01-0000 10 ten-gigabitethernet 1/0/1 # Configure a long static ARP entry that contains IP address 1.1.1.1, MAC address 00e0-fc01-0000, input interface VSI-interface 1, output interface Tunnel 1, and VSI a. [Sysname] arp static 1.1.1.1 00e0-fc01-0000 vsi-interface 1 tunnel 1 vsi a # Configure a long static ARP entry that contains IP address 1.1.1.1, MAC address 00e0-fc01-0000, input interface VSI-interface 1, output interface Ethernet instance 1 on Ten-GigabitEthernet 1/0/1, and VSI a. [Sysname] arp static 1.1.1.1 00e0-fc01-0000 vsi-interface 1 ten-gigabitethernet 1/0/1 service-in stance 1 vsi a display arp 7

reset arp arp timer aging Use arp timer aging to set the aging timer for dynamic ARP entries. Use undo arp timer aging to restore the default. arp timer aging { aging-minutes second aging-seconds } undo arp timer aging The aging timer for dynamic ARP entries is 20 minutes. System view aging-minutes: Specifies the aging timer in minutes. The value range for this argument is 1 to 1440. second aging-seconds: Specifies the aging timer in seconds. The value range for the aging-seconds argument is 5 to 86400. Each dynamic ARP entry in the ARP table has a limited lifetime, called an aging timer. The aging timer of a dynamic ARP entry is reset each time the dynamic ARP entry is updated. Dynamic ARP entries that are not updated before their aging timers expire are deleted from the ARP table. Set the aging timer for dynamic ARP entries as needed. For example, when you configure proxy ARP, set a short aging time so that invalid dynamic ARP entries can be deleted in a timely manner. # Set the aging timer for dynamic ARP entries to 10 minutes. [Sysname] arp timer aging 10 # Set the aging timer for dynamic ARP entries to 200 seconds. [Sysname] arp timer aging second 200 display arp timer aging display arp Use display arp to display ARP entries. display arp [ [ all dynamic multiport static ] [ slot slot-number ] vlan vlan-id interface interface-type interface-number ] [ count verbose ] Any view 8

network-operator all: Displays all ARP entries. dynamic: Displays dynamic ARP entries. multiport: Displays multiport ARP entries. static: Displays static ARP entries. slot slot-number: Specifies an IRF member device by its member ID. If you do not specify a member device, this command displays ARP entries for the master device. vlan vlan-id: Specifies a VLAN by its VLAN ID. The VLAN ID is in the range of 1 to 4094. interface interface-type interface-number: Specifies an interface by its type and number. If you do not specify an interface, this command displays ARP entries for all interfaces. count: Displays the number of ARP entries. verbose: Displays detailed information about ARP entries. This command displays information about ARP entries, including the IP address, MAC address, VLAN ID, output interface, entry type, and aging timer. # Display all ARP entries. <Sysname> display arp all IP address MAC address VLAN/VSI Interface/Link ID Aging Type 1.1.1.1 02e0-f102-0023 1 XGE1/0/1 -- S 1.1.1.2 00e0-fc00-0001 12 XGE1/0/2 960 D 1.1.1.3 00e0-fe50-6503 12 Tunnel1 960 D 1.1.1.4 000d-88f7-9f7d 12 0x1 960 D # Display detailed information about all ARP entries. IP address : 1.1.1.1 MAC address : 02e0-f102-0023 Type : Static Aging : -- Interface : XGE1/0/1 VLAN : 1 VPN instance : -- Link ID : -- VXLAN ID : -- VSI name : -- VSI interface : -- Nickname : 0x0000 IP address : 1.1.1.2 MAC address : 0015-e944-adc5 Type : Static Aging : 960 sec Interface : XGE1/0/2 VLAN : 12 VPN instance : -- Link ID : -- VXLAN ID : -- VSI name : -- VSI interface : -- Nickname : 0x0000 9

IP address : 1.1.1.3 MAC address : 0013-1234-0001 Type : Dynamic Aging : 960 sec Interface : Tunnel1 VLAN : 12 VPN instance : -- Link ID : -- VXLAN ID : -- VSI name : vpna VSI interface : Vsi1 Nickname : 0x0000 IP address : 1.1.1.4 MAC address : 0012-1234-0002 Type : Dynamic Aging : 960 sec Interface : -- VLAN : 12 VPN instance : -- Link ID : 0x1 VXLAN ID : -- VSI name : vpna VSI interface : Vsi1 Nickname : 0x0000 # Display the number of all ARP entries. <Sysname> display arp all count Total number of entries : 4 Table 1 Command output Field IP address MAC address VLAN/VSI Interface Link ID Aging Description IP address in an ARP entry. MAC address in an ARP entry. ID of the VLAN or index of the VSI to which the ARP entry belongs. This field displays hyphens (--) in either of the following situations: The ARP entry is an unresolved short static ARP entry. The output interface of the ARP entry does not belong to the VLAN or VSI. Output interface in an ARP entry. This field displays hyphens (--) in either of the following situations: The ARP entry is an unresolved short static ARP entry. The ARP entry is a multiport ARP entry and has no output interface information. To obtain the output interface information of the multiport ARP entry, look up the MAC address table according to the MAC address in the ARP entry. Link ID in an ARP entry. This field displays hyphens (--) if the ARP entry does not belong to any VSI. Aging time for an ARP entry in seconds. For a static ARP entry, this field always displays hyphens (--). The static ARP entry never ages out unless you delete it manually. For a dynamic ARP entry, this field displays hyphens (--) if the aging time is unknown. 10

Field Type VPN instance Service instance VXLAN ID VSI name VSI interface Nickname Total number of entries Description ARP entry type: D Dynamic. S Static. O OpenFlow. R Rule. M Multiport. I Invalid. Name of VPN instance. If no VPN instance is configured for the ARP entry, this field displays hyphens (--). Ethernet service instance in an ARP entry. This field displays hyphens (--) if no Ethernet service instance is specified for the Layer 2 Ethernet interface or Layer 2 aggregate interface in the ARP entry. ID of the VXLAN to which the ARP entry belongs. VXLAN ID is also called VNI. If the ARP entry does not belong to any VXLAN, this field displays hyphens (--). Name of the VSI to which the ARP entry belongs. If the ARP entry does not belong to any VSI, this field displays hyphens (--). Name of the gateway interface of the VSI. If no gateway interface is specified for the VSI, this field displays hyphens (--). Nickname of the ARP entry. The nickname is a string of four hexadecimal numbers, for example, 012a. For more information about the nickname, see TRILL Configuration Guide. Number of ARP entries. arp static reset arp display arp entry-limit Use display arp entry-limit to display the maximum number of ARP entries that a device supports. display arp entry-limit Any view network-operator # Display the maximum number of ARP entries that the device supports. <Sysname> display arp entry-limit ARP entries: 8192 11

display arp ip-address Use display arp ip-address to display the ARP entry for an IP address. display arp ip-address [ slot slot-number ] [ verbose ] Any view network-operator ip-address: Displays the ARP entry for the specified IP address. slot slot-number: Specifies an IRF member device by its member ID. If you do not specify a member device, this command displays information for the master device. verbose: Displays the detailed information about the specified ARP entry. The ARP entry information includes the IP address, MAC address, VLAN ID, output interface, entry type, and aging timer. # Display the ARP entry for the IP address 20.1.1.1. <Sysname> display arp 20.1.1.1 Type: S-Static D-Dynamic O-Openflow R-Rule M-Multiport I-Invalid IP address MAC address VLAN/VSI Interface Aging Type 20.1.1.1 00e0-fc00-0001 -- -- -- S arp static reset arp display arp openflow count Use display arp openflow count to display the number of OpenFlow ARP entries. display arp openflow count [ slot slot-number ] Any view network-operator slot slot-number: Specifies an IRF member device by its member ID. If you do not specify a member device, this command displays the number of OpenFlow ARP entries for the master device. 12

# Display the number of OpenFlow ARP entries. <Sysname> display arp openflow count Total number of OpenFlow ARP entries: 6 display arp timer aging Use display arp timer aging to display the aging timer of dynamic ARP entries. display arp timer aging Any view network-operator # Display the aging timer of dynamic ARP entries. <Sysname> display arp timer aging Current ARP aging time is 1200 seconds arp timer aging display arp vpn-instance Use display arp vpn-instance to display the ARP entries for a VPN instance. display arp vpn-instance vpn-instance-name [ count ] Any view network-operator vpn-instance-name: Specifies an MPLS L3VPN instance by its name, a case-sensitive string of 1 to 31 characters. The VPN instance name cannot contain any spaces. count: Displays the number of ARP entries. This command displays information about ARP entries for a VPN instance, including the IP address, MAC address, VLAN ID, output interface, entry type, and aging timer. # Display ARP entries for VPN instance test. <Sysname> display arp vpn-instance test 13

Type: S-Static D-Dynamic O-Openflow R-Rule M-Multiport I-Invalid IP address MAC address VLAN/VSI Interface Aging Type 20.1.1.1 00e0-fc00-0001 -- -- -- S arp static reset arp reset arp Use reset arp to clear ARP entries from the ARP table. reset arp { all dynamic interface interface-type interface-number multiport slot slot-number static } User view all: Clears all ARP entries. dynamic: Clears all dynamic ARP entries. multiport: Clears all multiport ARP entries. static: Clears all static ARP entries. slot slot-number: Specifies an IRF member device by its member ID. If you do not specify a member device, this command clears ARP entries for the master device. interface interface-type interface-number: Specifies an interface by its type and number. If you do not specify an interface, this command clears ARP entries for all interfaces. # Clear all static ARP entries. <Sysname> reset arp static arp static display arp 14

Gratuitous ARP commands arp ip-conflict log prompt Use arp ip-conflict log prompt to enable IP conflict notification. Use undo arp ip-conflict log prompt to restore the default. arp ip-conflict log prompt undo arp ip-conflict log prompt IP conflict notification is disabled. System view By default, the device performs the following operations if it is using the sender IP address of a received ARP packet: Sends a gratuitous ARP request. Displays an error message after the device receives an ARP reply about the conflict. You can use this command to enable the device to display error messages before sending a gratuitous ARP reply or request for conflict confirmation. # Enable IP conflict notification on the device. [Sysname] arp ip-conflict log prompt arp send-gratuitous-arp Use arp send-gratuitous-arp to enable periodic sending of gratuitous ARP packets on an interface. Use undo arp send-gratuitous-arp to disable the interface from periodically sending gratuitous ARP packets. arp send-gratuitous-arp [ interval interval ] undo arp send-gratuitous-arp Periodic sending of gratuitous ARP packets is disabled. Layer 3 Ethernet interface view Layer 3 Ethernet subinterface view 15

Layer 3 aggregate interface view Layer 3 aggregate subinterface view VXLAN VSI interface view VLAN interface view interval interval: Specifies the sending interval in the range of 200 to 200000 milliseconds. The default value is 2000 milliseconds. This feature takes effect on an interface only when the interface has an IP address and the data link layer state of the interface is up. This feature can send gratuitous ARP requests only for a VRRP virtual IP address, or the sending interface's primary IP address or manually configured secondary IP address. The primary IP address can be configured manually or automatically, whereas the secondary IP address must be configured manually. If you change the sending interval for gratuitous ARP packets, the configuration takes effect at the next sending interval. The sending interval for gratuitous ARP packets might be much longer than the set interval when any of the following conditions exist: This feature is enabled on multiple interfaces. Each interface is configured with multiple secondary IP addresses. A small sending interval is configured in the preceding cases. # Enable VLAN-interface 2 to send gratuitous ARP packets every 300 milliseconds. [Sysname] interface vlan-interface 2 [Sysname-Vlan-interface2] arp send-gratuitous-arp interval 300 gratuitous-arp mac-change retransmit Use gratuitous-arp mac-change retransmit to set the times and the interval for retransmitting a gratuitous ARP packet for the device MAC address change. Use undo gratuitous-arp mac-change retransmit to restore the default. gratuitous-arp mac-change retransmit times interval seconds undo gratuitous-arp mac-change retransmit The device sends a gratuitous packet for its MAC address change once only. System view 16

times: Specifies the times of retransmitting a gratuitous packet, in the range of 1 to 10. interval seconds: Specifies the interval for retransmitting a gratuitous packet, in the range of 1 to 10 seconds. The device sends a gratuitous ARP packet to inform other devices of its MAC address change. However, the other devices might fail to receive the packet because the device sends the gratuitous ARP packet once only by default. Use this command to configure gratuitous ARP retransmission parameters to ensure that the other devices can receive the packet. After you execute this command, the device will retransmit a gratuitous ARP packet for its MAC address change at the specified interval for the specified times. # Set the times to 3 and the interval to 5 for retransmitting a gratuitous ARP packet for the device MAC address change. [Sysname] gratuitous-arp mac-change retransmit 3 interval 5 gratuitous-arp-learning enable Use gratuitous-arp-learning enable to enable learning of gratuitous ARP packets. Use undo gratuitous-arp-learning enable to disable learning of gratuitous ARP packets. gratuitous-arp-learning enable undo gratuitous-arp-learning enable Learning of gratuitous ARP packets is enabled. System view The learning of gratuitous ARP packets feature allows a device to maintain its ARP table by creating or updating ARP entries based on received gratuitous ARP packets. When this feature is disabled, the device uses received gratuitous ARP packets to update existing ARP entries only. ARP entries are not created based on the received gratuitous ARP packets, which saves ARP table space. # Enable learning of gratuitous ARP packets. [Sysname] gratuitous-arp-learning enable 17

gratuitous-arp-sending enable Use gratuitous-arp-sending enable to enable sending gratuitous ARP packets upon receiving ARP requests whose sender IP address is on a different subnet. Use undo gratuitous-arp-sending enable to disable sending gratuitous ARP packets upon receiving ARP requests whose sender IP address is on a different subnet. gratuitous-arp-sending enable undo gratuitous-arp-sending enable A device does not send gratuitous ARP packets when it receives ARP requests whose sender IP address is on a different subnet. System view # Disable a device from sending gratuitous ARP packets upon receiving ARP requests whose sender IP address is on a different subnet. [Sysname] undo gratuitous-arp-sending enable 18

Proxy ARP commands display local-proxy-arp Use display local-proxy-arp to display the local proxy ARP status. display local-proxy-arp [ interface interface-type interface-number ] Any view network-operator interface interface-type interface-number: Specifies an interface by its type and number. If you do not specify an interface, this command displays the local proxy ARP status for all interfaces. You can use this command to check whether local proxy ARP is enabled or disabled. # Display the local proxy ARP status for VLAN-interface 2. <Sysname> display local-proxy-arp interface vlan-interface 2 Interface Vlan-interface2 Local Proxy ARP status: enabled local-proxy-arp enable display proxy-arp Use display proxy-arp to display the proxy ARP status. display proxy-arp [ interface interface-type interface-number ] Any view network-operator interface interface-type interface-number: Specifies an interface by its type and number. If you do not specify an interface, this command displays the proxy ARP status for all interfaces. You can use this command to check whether proxy ARP is enabled or disabled. 19

# Display the proxy ARP status on VLAN-interface 2. <Sysname> display proxy-arp interface vlan-interface 2 Interface Vlan-interface2 Proxy ARP status: disabled proxy-arp enable local-proxy-arp enable Use local-proxy-arp enable to enable local proxy ARP. Use undo local-proxy-arp enable to disable local proxy ARP. local-proxy-arp enable [ ip-range start-ip-address to end-ip-address ] undo local-proxy-arp enable Local proxy ARP is disabled. Layer 3 Ethernet interface view Layer 3 Ethernet subinterface view Layer 3 aggregate interface view Layer 3 aggregate subinterface view VXLAN VSI interface view VLAN interface view ip-range start-ip-address to end-ip-address: Specifies the IP address range for which local proxy ARP is enabled. The start IP address must be lower than or equal to the end IP address. Proxy ARP enables a device on a network to answer ARP requests for an IP address not on that network. With proxy ARP, hosts in different broadcast domains can communicate with each other as they do on the same network. Proxy ARP includes common proxy ARP and local proxy ARP. Common proxy ARP allows communication between hosts that connect to different Layer 3 interfaces and reside in different broadcast domains. Local proxy ARP allows communication between hosts that connect to the same Layer 3 interface and reside in different broadcast domains. If you execute this command multiple times, the most recent configuration takes effect. # Enable local proxy ARP on VLAN-interface 2. 20

[Sysname] interface vlan-interface 2 [Sysname-Vlan-interface2] local-proxy-arp enable # Enable local proxy ARP on VLAN-interface 2 for an IP address range. [Sysname] interface vlan-interface 2 [Sysname-Vlan-interface2] local-proxy-arp enable ip-range 1.1.1.1 to 1.1.1.20 display local-proxy-arp proxy-arp enable Use proxy-arp enable to enable proxy ARP. Use undo proxy-arp enable to disable proxy ARP. proxy-arp enable undo proxy-arp enable Proxy ARP is disabled. Layer 3 Ethernet interface view Layer 3 Ethernet subinterface view Layer 3 aggregate interface view Layer 3 aggregate subinterface view VXLAN VSI interface view VLAN interface view Proxy ARP enables a device on a network to answer ARP requests for an IP address not on that network. With proxy ARP, hosts in different broadcast domains can communicate with each other as they do on the same network. Proxy ARP includes common proxy ARP and local proxy ARP. Common proxy ARP allows communication between hosts that connect to different Layer 3 interfaces and reside in different broadcast domains. Local proxy ARP allows communication between hosts that connect to the same Layer 3 interface and reside in different broadcast domains. # Enable proxy ARP on VLAN-interface 2. [Sysname] interface vlan-interface 2 [Sysname-Vlan-interface2] proxy-arp enable 21

display proxy-arp 22

ARP snooping commands arp snooping enable Use arp snooping enable to enable ARP snooping. Use undo arp snooping enable to disable ARP snooping. arp snooping enable undo arp snooping enable ARP snooping is disabled. VLAN view # Enable ARP snooping for VLAN 2. [Sysname] vlan 2 [Sysname-vlan2] arp snooping enable display arp snooping Use display arp snooping to display ARP snooping entries. display arp snooping [ vlan vlan-id ] [ slot slot-number ] [ count ] display arp snooping ip ip-address [ slot slot-number ] Any view network-operator vlan vlan-id: Displays ARP snooping entries for a VLAN. The vlan-id argument is in the range of 1 to 4094. count: Displays the number of the ARP snooping entries. ip ip-address: Displays the ARP snooping entry for the specified IP address. slot slot-number: Specifies an IRF member device by its member ID. If you do not specify a member device, this command displays ARP snooping entries for the master device. 23