12-11-2018 02:34 PM - edited 03-08-2019 04:47 PM
Hello, I am using Dynamic Arp Inspection (DAI) in assocation with DHCP Snooping.
My question is, is it safe to enable DAI before the DHCP snooping table has fully populated with all possible DHCP enabled devices ?
If DAI sees traffic come through the switch from a client but there is no entry yet in the DHCP table, will it block that traffic ?
n.b. a scenario might be if a client pulled DHCP before DHCP snooping was enabled.
Solved! Go to Solution.
12-11-2018 03:16 PM - edited 12-11-2018 03:20 PM
Hello
@tedauction wrote:
Hello, I am using Dynamic Arp Inspection (DAI) in assocation with DHCP Snooping.
My question is, is it safe to enable DAI before the DHCP snooping table has fully populated with all possible DHCP enabled devices ?
If DAI sees traffic come through the switch from a client but there is no entry yet in the DHCP table, will it block that traffic ?
n.b. a scenario might be if a client pulled DHCP before DHCP snooping was enabled.
No it wont be safe to enable DAI on a switch without having the snooping D/B being populated first, as DAI wont be able to validate against the snooping D/B for valid entries, The only way to bypass this would be to apply static DAI filter list as this is always checked prior to checking the snooping D/B
12-11-2018 03:16 PM - edited 12-11-2018 03:20 PM
Hello
@tedauction wrote:
Hello, I am using Dynamic Arp Inspection (DAI) in assocation with DHCP Snooping.
My question is, is it safe to enable DAI before the DHCP snooping table has fully populated with all possible DHCP enabled devices ?
If DAI sees traffic come through the switch from a client but there is no entry yet in the DHCP table, will it block that traffic ?
n.b. a scenario might be if a client pulled DHCP before DHCP snooping was enabled.
No it wont be safe to enable DAI on a switch without having the snooping D/B being populated first, as DAI wont be able to validate against the snooping D/B for valid entries, The only way to bypass this would be to apply static DAI filter list as this is always checked prior to checking the snooping D/B
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide