<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dynamic ARP Inspection (DAI) in Cloud Networking Platform</title>
    <link>https://community.cisco.com/t5/cloud-networking-platform/dynamic-arp-inspection-dai/m-p/5457846#M13358</link>
    <description>&lt;P&gt;Sorry if this is the wrong place, I couldn't find a general network section.  My switches are Netgear (I know, I know), and I have DHCP Snooping enabled, and I'm also thinking about enabling Dynamic ARP Inspection (DAI).  Do you guys have DHCP Snooping and DAI enabled at your production network?&lt;/P&gt;&lt;P&gt;I know DAI looks at the DHCP Snooping database to compare the MAC and IP, but with people working from their home, what happens when they return to work since their laptops will not be in the DHCP Snooping database.  I know you can manually add them but that's a lot of work.&lt;/P&gt;&lt;P&gt;Also, what about 802.1X authentication, anyone using them on their production network?&lt;/P&gt;&lt;P&gt;I'm trying to make my production network more secure.&lt;/P&gt;</description>
    <pubDate>Mon, 30 Aug 2021 15:17:35 GMT</pubDate>
    <dc:creator>tantony</dc:creator>
    <dc:date>2021-08-30T15:17:35Z</dc:date>
    <item>
      <title>Dynamic ARP Inspection (DAI)</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/dynamic-arp-inspection-dai/m-p/5457846#M13358</link>
      <description>&lt;P&gt;Sorry if this is the wrong place, I couldn't find a general network section.  My switches are Netgear (I know, I know), and I have DHCP Snooping enabled, and I'm also thinking about enabling Dynamic ARP Inspection (DAI).  Do you guys have DHCP Snooping and DAI enabled at your production network?&lt;/P&gt;&lt;P&gt;I know DAI looks at the DHCP Snooping database to compare the MAC and IP, but with people working from their home, what happens when they return to work since their laptops will not be in the DHCP Snooping database.  I know you can manually add them but that's a lot of work.&lt;/P&gt;&lt;P&gt;Also, what about 802.1X authentication, anyone using them on their production network?&lt;/P&gt;&lt;P&gt;I'm trying to make my production network more secure.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 15:17:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/dynamic-arp-inspection-dai/m-p/5457846#M13358</guid>
      <dc:creator>tantony</dc:creator>
      <dc:date>2021-08-30T15:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic ARP Inspection (DAI)</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/dynamic-arp-inspection-dai/m-p/5457847#M13359</link>
      <description>&lt;P&gt;If your clients connect to the switch and get a dhcp address  the snooping table will fill. Only client with static assigned  address need to have a static entry in the switch.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 16:43:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/dynamic-arp-inspection-dai/m-p/5457847#M13359</guid>
      <dc:creator>ww^</dc:creator>
      <dc:date>2021-08-30T16:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic ARP Inspection (DAI)</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/dynamic-arp-inspection-dai/m-p/5457848#M13360</link>
      <description>&lt;P&gt;Wouldn't the client's MAC already have to be in the DHCP Snooping table even to get DHCP?  I'm talking about a new device that never connected before.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 17:19:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/dynamic-arp-inspection-dai/m-p/5457848#M13360</guid>
      <dc:creator>tantony</dc:creator>
      <dc:date>2021-08-30T17:19:30Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic ARP Inspection (DAI)</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/dynamic-arp-inspection-dai/m-p/5457849#M13361</link>
      <description>&lt;P&gt;No.&lt;/P&gt;&lt;P&gt;Dhcp snooping prevent dhcp server side packets(offer,ack) from being send from untrusted ports.  (You have to trust ports to the dhcp server like trunks and the port the dhcp server is on)&lt;/P&gt;&lt;P&gt;So it prevents from unwanted dhcp servers on your network&lt;/P&gt;&lt;P&gt;And it fills the dhcp snooping table based on the dhcp packets.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 17:24:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/dynamic-arp-inspection-dai/m-p/5457849#M13361</guid>
      <dc:creator>ww^</dc:creator>
      <dc:date>2021-08-30T17:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic ARP Inspection (DAI)</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/dynamic-arp-inspection-dai/m-p/5457850#M13362</link>
      <description>&lt;P&gt;Ah right, I forgot about that part.  I already have the trunk and lags as trusted, and rest untrusted.  &lt;/P&gt;&lt;P&gt;So far, I've only enabled DAI on one of the switch, and everything is working.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 17:33:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/dynamic-arp-inspection-dai/m-p/5457850#M13362</guid>
      <dc:creator>tantony</dc:creator>
      <dc:date>2021-08-30T17:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic ARP Inspection (DAI)</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/dynamic-arp-inspection-dai/m-p/5457851#M13363</link>
      <description>&lt;P&gt;Love to hear if anyone is using 802.1X on their network also.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 17:34:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/dynamic-arp-inspection-dai/m-p/5457851#M13363</guid>
      <dc:creator>tantony</dc:creator>
      <dc:date>2021-08-30T17:34:14Z</dc:date>
    </item>
  </channel>
</rss>

