Sample Two: One Switch Supports Dai - Cisco WS-SUP32-GE-3B - Supervisor Engine 32 Software Configuration Manual

Software configuration guide
Hide thumbs Also See for WS-SUP32-GE-3B - Supervisor Engine 32:
Table of Contents

Advertisement

DAI Configuration Samples
----
SwitchB#
If Host 2 then sends out an ARP request with the IP address 1.1.1.1 and the MAC address
0001.0001.0001, the packet is forwarded and the statistics are updated appropriately:
SwitchB# show ip arp inspection statistics vlan 1
Vlan
----
Vlan
----
Vlan
----
SwitchB#
If Host 2 attempts to send an ARP request with the IP address 1.1.1.2, DAI drops the request and logs a
system message:
00:18:08: %SW_DAI-4-DHCP_SNOOPING_DENY: 1 Invalid ARPs (Req) on Fa3/4, vlan
1.([0001.0001.0001/1.1.1.2/0000.0000.0000/0.0.0.0/01:53:21 UTC Fri May 23 2003])
SwitchB#
The statistics display as follows:
SwitchB# show ip arp inspection statistics vlan 1
Vlan
----
Vlan
----
Vlan
----
SwitchB#

Sample Two: One Switch Supports DAI

This procedure shows how to configure DAI when Switch B shown in
support DAI or DHCP snooping.
If switch Switch B does not support DAI or DHCP snooping, configuring Fast Ethernet port 6/3 on
Switch A as trusted creates a security hole because both Switch A and Host 1 could be attacked by either
Switch B or Host 2.
To prevent this possibility, you must configure Fast Ethernet port 6/3 on Switch A as untrusted. To permit
ARP packets from Host 2, you must set up an ARP ACL and apply it to VLAN 1. If the IP address of
Host 2 is not static, which would make it impossible to apply the ACL configuration on Switch A, you
must separate Switch A from Switch B at Layer 3 and use a router to route packets between them.
Catalyst Supervisor Engine 32 PISA Cisco IOS Software Configuration Guide, Release 12.2ZY
35-20
-----------------
1
0
Forwarded
---------
1
1
DHCP Permits
ACL Permits
------------
-----------
1
1
Dest MAC Failures
-----------------
1
0
Forwarded
---------
1
1
DHCP Permits
ACL Permits
------------
-----------
1
1
Dest MAC Failures
-----------------
1
0
----------------------
0
Dropped
DHCP Drops
-------
----------
0
0
Source MAC Failures
-------------------
0
IP Validation Failures
----------------------
0
Dropped
DHCP Drops
-------
----------
1
1
Source MAC Failures
-------------------
0
IP Validation Failures
----------------------
0
Chapter 35
Configuring Dynamic ARP Inspection
ACL Drops
----------
0
0
ACL Drops
----------
0
0
Figure 35-2 on page 35-3
does not
OL-11439-03

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst supervisor engine 32 pisa

Table of Contents