- For individual users
- Instant access to solutions
- Ask your tech questions
- Start your 30-day Free Trial
Main Topics
Browse All TopicsI recently discovered the 'ip sticky-arp' command in Cisco devices. However, I have a mesh network of Cisco/Foundry (Brocade) devices and do not know how to implement a similiar command for Foundry devices.
I would also like to know more regarding the operation of 'ip sticky-arp'. I imagine it does not release IP-MAC associations in the mac-address table until the source mac comes from a different port and then the switch annotates the change. However, I have heard something regarding Layer 3 ports do not operate in the same manner and switching devices on that Layer 3 port could cause a problem if 'ip sticky-arp' is applied to them.
Any information would be greatly apprecaited. Thank you.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Business Accounts
Answer for Membership
by: harbor235Posted on 2009-10-23 at 06:51:07ID: 25644391
"Sticky ARP prevents MAC address spoofing by ensuring that ARP entries (IP address, MAC address, and source VLAN) do not get overridden. The switch maintains ARP entries in order to forward traffic to end devices or other switches. ARP entries are usually updated periodically or modified when ARP broadcasts are received. During an attack, ARP broadcasts are sent using a spoofed MAC address (with a legitimate IP address) so that the switch learns the legitimate IP address with the spoofed MAC address and begins to forward traffic to that MAC address. With sticky ARP enabled, the switch learns the ARP entries and does not accept modifications received through ARP broadcasts. If you attempt to override the sticky ARP configuration, you will receive an error message. "
Foundry has port security and static arp entries, what is missing is the feature to notice the change via broadcast and alrm based on the attempt. Foundry is a decent device but if you want advanced features and functionality this is one of the descriminators with top of the line equipment.
harbor235 ;}