<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: device-tracking mode guard vs legacy DAI in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246345#M1118717</link>
    <description>&lt;P&gt;Both DAI and IPSG match mac to IP' the different is DAI is inspect only ARP packet where IPSG inspect data packet.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jan 2025 10:10:12 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-01-13T10:10:12Z</dc:date>
    <item>
      <title>device-tracking mode guard vs legacy DAI</title>
      <link>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5245750#M1118676</link>
      <description>&lt;P&gt;reading Feature history of SISF&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9400/software/release/17-12/configuration_guide/sec/b_1712_sec_9400_cg/configuring_sisf_based_device_tracking.html#reference_bpn_yp3_bxb" target="_blank"&gt;Security Configuration Guide, Cisco IOS XE Dublin 17.12.x (Catalyst 9400 Switches) - Configuring Switch Integrated Security Features [Support] - Cisco&lt;/A&gt;&amp;nbsp;i have a feeling that device-tracking mode guard is an alternative to legacy DAI.&lt;BR /&gt;Unfortunately official documentation is not quite detailed on topic. Can anyone please shed a light on it?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 16:51:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5245750#M1118676</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2025-01-10T16:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: device-tracking mode guard vs legacy DAI</title>
      <link>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246305#M1118714</link>
      <description>&lt;P&gt;I dont think it same as DAI but it same as IPSG&amp;nbsp; where it check IP-MAC for data packet not as DAI check only ARP packet&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 08:00:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246305#M1118714</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-13T08:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: device-tracking mode guard vs legacy DAI</title>
      <link>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246323#M1118715</link>
      <description>&lt;P&gt;Yes, it does fulfil the same role as DAI. See the following portion of the SISF documentation:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9400/software/release/17-12/configuration_guide/sec/b_1712_sec_9400_cg/configuring_sisf_based_device_tracking.html#reference_bpn_yp3_bxbv" target="_blank" rel="noopener"&gt;Example: Detecting and Preventing Spoofing&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 09:17:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246323#M1118715</guid>
      <dc:creator>Torbjørn</dc:creator>
      <dc:date>2025-01-13T09:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: device-tracking mode guard vs legacy DAI</title>
      <link>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246341#M1118716</link>
      <description>&lt;P&gt;i tend to stay w/ same interpretation. but it seems like we have dispute here...&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 09:58:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246341#M1118716</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2025-01-13T09:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: device-tracking mode guard vs legacy DAI</title>
      <link>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246345#M1118717</link>
      <description>&lt;P&gt;Both DAI and IPSG match mac to IP' the different is DAI is inspect only ARP packet where IPSG inspect data packet.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 10:10:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246345#M1118717</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-13T10:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: device-tracking mode guard vs legacy DAI</title>
      <link>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246384#M1118718</link>
      <description>&lt;P&gt;Do you have anything to add here&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113909"&gt;@jedolphi&lt;/a&gt;?&lt;BR /&gt;I really liked the&amp;nbsp;&lt;SPAN&gt;BRKENS-3555 presentation and figure you might have something to add to this discussion.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 12:11:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246384#M1118718</guid>
      <dc:creator>Torbjørn</dc:creator>
      <dc:date>2025-01-13T12:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: device-tracking mode guard vs legacy DAI</title>
      <link>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246543#M1118731</link>
      <description>&lt;P&gt;thanks for calling&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113909"&gt;@jedolphi&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;would appreciate hearing from him&lt;BR /&gt;meanwhile on the slide 157 of the BRKENS-3555 the is more clear statement about protections SISF does:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="andydoesntlikeuucp_0-1736783166603.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237485i46931DABE257487B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="andydoesntlikeuucp_0-1736783166603.png" alt="andydoesntlikeuucp_0-1736783166603.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;no DAI functionality&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2025 15:47:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246543#M1118731</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2025-01-13T15:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: device-tracking mode guard vs legacy DAI</title>
      <link>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246853#M1118769</link>
      <description>&lt;P&gt;Instead of comparing exact functionality of the two, perhaps it's better to focus on outcomes.. The two things are implemented differently. What specific outcomes are we trying to compare?&lt;/P&gt;
&lt;P&gt;DAI relies on DHCP Snooping table, which is not distributed across the ENs (Fabric Edge Nodes).&lt;/P&gt;
&lt;P&gt;SISF binding table is distributed across the ENs via LISP.&lt;/P&gt;
&lt;P&gt;In DAI, if a corresponding entry (src MAC / IP) is not present from DHCP snooping, the incoming ARP is dropped. It will dropped as long as no DHCP entry in the table.&lt;/P&gt;
&lt;P&gt;In SISF/SDA case, if corresponding entry is not present in SISF binding table, the incoming ARP packet will be dropped until the source is verified and MAC-IP binding integrity is confirmed. This does not rely on binding learned from the DHCP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 09:56:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246853#M1118769</guid>
      <dc:creator>jedolphi</dc:creator>
      <dc:date>2025-01-14T09:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: device-tracking mode guard vs legacy DAI</title>
      <link>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246910#M1118771</link>
      <description>&lt;P&gt;Hi Jerom&lt;BR /&gt;General idea was leverage maximum of SIFS in any environment not only LISP'ed those. Some customers like DAI much :0) But from recent studying of the topic it doesn sound nowadays SISF is able to replace it.&lt;BR /&gt;btw, let me to correct u, but static ip-source-bindings or ARP-ACLs allow bypassing lack of DHCPs-binding entries within DAI-framework.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 12:08:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246910#M1118771</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2025-01-14T12:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: device-tracking mode guard vs legacy DAI</title>
      <link>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246985#M1118773</link>
      <description>&lt;P&gt;Right, sorry, ask an SDA guy a general question and he gives an SDA answer, even though it was not an SDA question, my mistake!&lt;/P&gt;
&lt;P&gt;There is overlap between DAI and SISF DT, but not full parity yet e.g.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Both can protect against invalid IP-MAC pairs&lt;/LI&gt;
&lt;LI&gt;DAI can do burst limits, DT does it differently&lt;/LI&gt;
&lt;LI&gt;DAI learns from DHCP snooping, DT learns from gleaning DHCP and ARP&lt;/LI&gt;
&lt;LI&gt;DAI can shut violated port, DT not. Etc...&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 14:28:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246985#M1118773</guid>
      <dc:creator>jedolphi</dc:creator>
      <dc:date>2025-01-14T14:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: device-tracking mode guard vs legacy DAI</title>
      <link>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246990#M1118774</link>
      <description>&lt;P&gt;hopefully i'll make to the time when Cisco includes DAI into SIFS ;0)&lt;BR /&gt;thank you for your hints.&lt;BR /&gt;To everyone who is interesting in the topic i've found nice w/p on the CCO&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/switches/catalyst-9000/white-paper-c11-743346.html" target="_blank"&gt;Cisco Catalyst 9000 Family Switch Integrated Security Features (SISF) White Paper - Cisco&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 14:25:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5246990#M1118774</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2025-01-14T14:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: device-tracking mode guard vs legacy DAI</title>
      <link>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5247018#M1118777</link>
      <description>&lt;P&gt;No we thanks to you for this very informal Q.&lt;/P&gt;
&lt;P&gt;Keep ask&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a nice day&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 15:15:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/device-tracking-mode-guard-vs-legacy-dai/m-p/5247018#M1118777</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-14T15:15:25Z</dc:date>
    </item>
  </channel>
</rss>

