Concept Guide
Broadcast An attacker can broadcast an ARP reply that species FF:FF:FF:FF:FF:FF as the gateway’s MAC address, resulting
in all clients broadcasting all internet-bound packets.
MAC ooding An attacker can send fraudulent ARP messages to the gateway until the ARP cache is exhausted, after which,
trac from the gateway is broadcast.
Denial of service An attacker can send a fraudulent ARP messages to a client to associate a false MAC address with the gateway
address, which would blackhole all internet-bound packets from the client.
NOTE: Dynamic ARP inspection (DAI) uses entries in the L2SysFlow CAM region, a sub-region of SystemFlow. One CAM entry is
required for every DAI-enabled VLAN. You can enable DAI on up to 16 VLANs on a system.
Conguring Dynamic ARP Inspection
To enable dynamic ARP inspection, use the following commands.
1 Enable DHCP snooping.
2 Validate ARP frames against the DHCP snooping binding table.
INTERFACE VLAN mode
arp inspection
Examples of Viewing the ARP Information
To view entries in the ARP database, use the show arp inspection database command.
DellEMC#show arp inspection database
Protocol Address Age(min) Hardware Address Interface VLAN CPU
---------------------------------------------------------------------
Internet 10.1.1.251 - 00:00:4d:57:f2:50 Gi 1/2 Vl 10 CP
Internet 10.1.1.252 - 00:00:4d:57:e6:f6 Gi 1/1 Vl 10 CP
Internet 10.1.1.253 - 00:00:4d:57:f8:e8 Gi 1/3 Vl 10 CP
Internet 10.1.1.254 - 00:00:4d:69:e8:f2 Gi 1/5 Vl 10 CP
DellEMC#
To see how many valid and invalid ARP packets have been processed, use the show arp inspection statistics command.
DellEMC#show arp inspection statistics
Dynamic ARP Inspection (DAI) Statistics
---------------------------------------
Valid ARP Requests : 0
Valid ARP Replies : 1000
Invalid ARP Requests : 1000
Invalid ARP Replies : 0
DellEMC#
Conguring dynamic ARP inspection-limit
To congure dynamic ARP inspection rate limit on a port, perform the following task.
1 Enter into global conguration mode.
EXEC Privilege mode
configure terminal
2 Select the interface to be congured.
CONFIGURATION mode
286
Dynamic Host Conguration Protocol (DHCP)