Users Guide

Table Of Contents
=======================================================================================
10.1.1.3 14:18:77:0d:05:e9 3600 D port-channel10
Dynamic ARP inspection
Dynamic Address Resolution Protocol (ARP) Inspection (DAI) is a security feature that protects LAN networks from man-in-the-middle
ARP spoong attacks.
When you enable DAI, the switch intercepts ARP packets on DAI-enabled VLANs. The switch then compares the source IP and source
MAC addresses, VLAN, and the port of the received packet with the DHCP snooping binding table. If the information in the packet does
not match an entry in the DHCP snooping binding table, the switch drops the packet.
NOTE: Dell EMC Networking recommends enabling DAI before enabling DHCP snooping on the system.
DAI violation logging
You can congure the system to log DAI validation failures corresponding to ARP packets. DAI violations are logged in the console if it is
enabled. DAI violation logging is disabled by default.
If you congure an interface as trusted, the switch interprets ARP packets that ingress the interface from hosts as legitimate packets. By
default, all interfaces are in DAI untrusted state.
For DAI to work, enable the DHCP snooping feature on the switch. DAI is disabled by default.
DAI statistics
The system maintains DAI statistics that contain the following details:
Valid ARP requests
Invalid ARP requests
Valid ARP replies
Invalid ARP replies
You can clear the DAI statistics using the clear ip arp inspection statistics command.
DAI trusted interfaces
By default, all ports are untrusted and all packets go through the DAI validation process on all DAI-enabled VLANs. You can congure an
interface to skip ARP inspection by conguring the interface as trusted.
NOTE
: Dell EMC Networking recommends conguring the arp inspection-trust command on the DHCP snooping trusted
interfaces when DAI is enabled for a VLAN.
Restrictions for Dynamic ARP Inspection
Dynamic ARP Inspection with VxLAN bridges is not supported.
Maximum number of supported Dynamic ARP Inspection entries is 2000.
Enable Dynamic ARP Inspection
Enable DHCP snooping. For more information about conguring DHCP snooping, see DHCP snooping.
Enable Dynamic ARP Inspection in a VLAN in INTERFACE VLAN mode.
arp inspection
Enable Dynamic ARP Inspection violation logging
Use the following command in CONFIGURATION mode:
arp inspection violation logging
System management
183