Default Dai Configuration; Dai Configuration Guidelines And Restrictions - Cisco WS-SUP32-GE-3B - Supervisor Engine 32 Software Configuration Manual

Software configuration guide
Hide thumbs Also See for WS-SUP32-GE-3B - Supervisor Engine 32:
Table of Contents

Advertisement

Chapter 35
Configuring Dynamic ARP Inspection
You use the ip arp inspection log-buffer global configuration command to configure the number of
entries in the buffer and the number of entries needed in the specified interval to generate system
messages. You specify the type of packets that are logged by using the ip arp inspection vlan logging
global configuration command. For configuration information, see the
section on page

Default DAI Configuration

Table 35-1
Table 35-1
Feature
DAI
Interface trust state
Rate limit of incoming ARP packets
ARP ACLs for non-DHCP environments
Validation checks
Log buffer
Per-VLAN logging

DAI Configuration Guidelines and Restrictions

When configuring DAI, follow these guidelines and restrictions:
OL-11439-03
35-12.
shows the default DAI configuration.
Default DAI Configuration
DAI is an ingress security feature; it does not perform any egress checking.
DAI is not effective for hosts connected to switches that do not support DAI or that do not have this
feature enabled. Because man-in-the-middle attacks are limited to a single Layer 2 broadcast
domain, separate the domain with DAI checks from the one with no checking. This action secures
the ARP caches of hosts in the domain enabled for DAI.
DAI depends on the entries in the DHCP snooping binding database to verify IP-to-MAC address
bindings in incoming ARP requests and ARP responses. Make sure to enable DHCP snooping to
permit ARP packets that have dynamically assigned IP addresses. For configuration information, see
Chapter 34, "Configuring DHCP Snooping."
Catalyst Supervisor Engine 32 PISA Cisco IOS Software Configuration Guide, Release 12.2ZY
"Configuring DAI Logging"
Default Setting
Disabled on all VLANs.
All interfaces are untrusted.
The rate is 15 pps on untrusted interfaces, assuming that
the network is a Layer 2-switched network with a host
connecting to as many as 15 new hosts per second.
The rate is unlimited on all trusted interfaces.
The burst interval is 1 second.
No ARP ACLs are defined.
No checks are performed.
When DAI is enabled, all denied or dropped ARP
packets are logged.
The number of entries in the log is 32.
The number of system messages is limited to 5 per
second.
The logging-rate interval is 1 second.
All denied or dropped ARP packets are logged.
Default DAI Configuration
35-5

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst supervisor engine 32 pisa

Table of Contents