09-28-2021 10:56 AM
Hello all,
This may be a silly question, but I've been reading up on IP Device-Tracking, and per Cisco's description, "The main IPDT task is to keep track of connected hosts (association of MAC and IP address)."
I guess I'm trying to see why we need IPDT when we already have an ARP cache that associates MAC and IP addresses for hosts. I suppose IPDT does send out periodic ARP probes so the IPDT table is perhaps more "current" than the ARP cache, but aside from that I'm not sure why we need IPDT when we already have ARP (I mean, I know there must be a reason as that's a lot of code to write for IPDT, but I just need help seeing the reason
Solved! Go to Solution.
09-29-2021 03:56 AM
short answer is arp responses ( relation MAC-address IP-address) can be spoofed!
goal for IPDT is to keep MAC + IP consistent with MAC + switchport, to increase security
ARP by itself has no registration of switchport
09-29-2021 06:22 AM
If you don't have any features enabled that need IPDT then it is only a nice-to-have database of IP-MAC-Port.
But if you are running any of the following features IPDT is needed:
"IPDT and its ARP probes sent out of a given interface are used for these features:
09-29-2021 03:56 AM
short answer is arp responses ( relation MAC-address IP-address) can be spoofed!
goal for IPDT is to keep MAC + IP consistent with MAC + switchport, to increase security
ARP by itself has no registration of switchport
09-29-2021 06:22 AM
If you don't have any features enabled that need IPDT then it is only a nice-to-have database of IP-MAC-Port.
But if you are running any of the following features IPDT is needed:
"IPDT and its ARP probes sent out of a given interface are used for these features:
09-29-2021 08:07 AM
Great! Thanks so much for the replies! I see now that IPDT also tracks the switchport and also what looks like a privilege level, so much different than ARP, and i see how IPDT could be used for the services mentioned. Thanks again!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide