05-21-2025 01:47 PM
Hi ,
If the Cisco 9800 WLC is connected to the core network via a Layer 3 link, how is this setup feasible? Cisco recommends avoiding the use of SVIs on the WLC side. Instead, it is best practice to configure the SVI on the core switch and use the ip helper-address command on that SVI.
In such a design, how can ARP spoofing attacks targeting wireless client devices be mitigated?"
Thanks
05-21-2025 10:03 PM
You can enable ARP Proxy inside the Policy Profile >> Advanced tab.
05-22-2025 12:13 AM
And in fact ARP proxy is generally recommended best practice.
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/technical-reference/c9800-best-practices.html#AddressResolutionProtocolARPproxy
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide