cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
183
Views
5
Helpful
4
Replies
Beginner

Dynamic ARP Inspection with no dhcp in environment

My question is in regards to Dynamic ARP Inspection. It was recommended that we enable it on our switches as part of the hardening process, but it uses the switch’s DHCP snooping database to allow ARP requests. As we do not use DHCP in the environment, it looks to me like I will have to manually add and remove the static IPs every time the environment is changed. Is there a better way to go about this? Basically we are looking for a control to help prevent ARP poisoning and IP spoofing on the network. We use Nexus switches attached to our VBlock, and there is no DHCP in the environment. 

 

Thanks in advance!

1 ACCEPTED SOLUTION

Accepted Solutions
Highlighted
VIP Engager

Re: Dynamic ARP Inspection with no dhcp in environment

Hi,

I think we need DHCP enabled on the network and it is pre-requirement for the same. 

 

Regards,
Deepak Kumar,
Resume duty after a long holiday
4 REPLIES 4

Re: Dynamic ARP Inspection with no dhcp in environment

There seems to be no way around it, if you want Dynamic ARP Inspection in an environment with no DHCP, you need to do manual work.

From the configuration guide, you still need the dhcp feature enabled though.

If you want DAI to use static IP-MAC address bindings to determine if ARP packets are valid, ensure that the DHCP snooping feature is enabled and that you have configured the static IP-MAC address bindings.”

Configuring Dynamic ARP Inspection

 

Beginner

Re: Dynamic ARP Inspection with no dhcp in environment

Thank you for the reply Hector! I really appreciate the validation!

Highlighted
VIP Engager

Re: Dynamic ARP Inspection with no dhcp in environment

Hi,

I think we need DHCP enabled on the network and it is pre-requirement for the same. 

 

Regards,
Deepak Kumar,
Resume duty after a long holiday
Beginner

Re: Dynamic ARP Inspection with no dhcp in environment

Thank you for the confirmation Deepak!!
CreatePlease to create content
Content for Community-Ad
July's Community Spotlight Awards