4.7.8 DAI – Dynamic ARP Inspection
Dynamic ARP Inspection is a secure feature. Several types of attacks can be launched against a host or devices connected to
Layer 2 networks by "poisoning" the ARP caches. This feature is used to block such attacks. Only valid ARP requests and
responses can go through DUT.
4.7.8.1 Global Configuration
The Security > DAI > Global Configuration page is used to enable ARP inspection globally for the switch, to validate address
information in each packet, and configure logging.
◆DAI Status – Enables ARP Inspection globally. (Default: Disabled)
◆DAI Check Content In ARP Packet – Enables extended ARP Inspection Validation if any of the following options are enabled.
(Default: Disabled)
Destination MAC address – Validates the destination MAC address in the Ethernet header against the target MAC
address in the body of ARP responses.
IP address – Checks the ARP body for invalid and unexpected IP addresses. Sender IP addresses are checked in
all ARP requests and responses, while target IP addresses are checked only in ARP responses.
Source MAC Address – Validates the source MAC address in the Ethernet header against the sender MAC
address in the ARP body. This check is performed on both ARP requests and responses.
4.7.8.2 VLAN Configuration
The Security > DAI > VLAN Configuration page is used to enable ARP inspection for any VLAN and to specify the ARP ACL to
use.
ARP Inspection VLAN ID – Selects any configured VLAN. (Default: 1)
ARP Inspection VLAN Status – Enables ARP Inspection for the selected VLAN. (Default: Disabled)
ARP Inspection ACL Name
ARP ACL – Allows selection of any configured ARP ACLs. (Default: None)
Static – When an ARP ACL is selected, and static mode is also selected, the switch only performs ARP Inspection
and bypasses validation against the DHCP Snooping Bindings database. When an ARP ACL is selected, but static
mode is not selected, the switch first performs ARP Inspection and then validation against the DHCP Snooping
Bindings database. (Default: Disabled)
User's Manual of SGS-5240 Series Managed Switch
227