Netgear M5300-52G-POE+ (GSM7252PSv1h2) - ProSAFE 48+4 L2+ POE Stackable Managed Switch Administrator's Guide

Page of 721
Security Management 
386
Managed Switches 
6. 
Configure port 1/0/1 as trusted. 
a. Select Security > Control > Dynamic ARP Inspection > DAI Interface 
Configuration
b.  Select the Interface 1/0/1 check box.
c.  For the Trust Mode, select Enable.
d.  Click Apply
A screen similar to the following displays.
Now ARP packets from the DHCP client will go through; however ARP packets from the 
static client are dropped, since it does have a DHCP snooping entry. It can be overcome by 
static configuration as described in the following section, 
386.
Static Mapping
The example is shown as CLI commands and as a web interface procedure.
CLI: Configure Static Mapping
1. 
Create an ARP ACL.
(Netgear Switch) (Config)# arp access-list ArpFilter
2. 
Configure the rule to allow the static client.
 (Netgear Switch) (Config-arp-access-list)# permit ip host 192.168.10.2 
      mac host 00:11:85:ee:54:e9
 
3. 
Configure ARP ACL used for VLAN 1.
(Netgear Switch) (Config)# ip arp inspection filter ArpFilter vlan 1