Dynamic ARP Inspection (DAI) working principle and test

Source: Internet
Author: User
Tags manual

I. Working principle:

A. To determine the MAC address of an illegal access in a network based on a DHCP snooping or manual form of MAC address and IP address binding table

B. At the same time, to prevent malicious ARP spoofing, you can also limit the ARP request packets of the interface

---Test found that ARP requests and replies for untrusted ports (including unreasonable ARP) are discarded, so it is not necessary to make a speed limit on a untrusted port (no manual modification of the DHCP binding table, or exclusion with ARP access-list).

Reference Link: http://wenku.baidu.com/view/cda2e815c5da50e2534d7f05.html

Two. Test topology:

Test switch iOS:

--cisco IOS Software, C3560 Software (c3560-ipservicesk9-m), Version 12.2 (+) SE3, release Software (FC1)

Three. Configuration steps:

A. Switches:

① Global Open DHCP snooping

IPDHCP snooping

② DHCP snooping enabled on VLAN 11

IPDHCP Snooping VLAN 11

③ specifies that the interface to the R2 (DHCP server) is a trusted interface

Interface FASTETHERNET0/2

IP DHCP snooping Trust

④ on the VLAN 11 to open Dai

ip arp inspection vlan 11

B.DHCP Server configuration:

① Set IP address pool

IP DHCP Pool dhcppool

Network 10.1.1.0 255.255.255.0

Default-router 10.1.1.2

② Trust 82 option

Interface gigabitethernet0/0

IP DHCP relay information trusted

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.