cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
223
Views
2
Helpful
2
Replies

WLC 9800 secuirty hardening

bluesea2010
Level 5
Level 5

Hi ,

If the Cisco 9800 WLC is connected to the core network via a Layer 3 link, how is this setup feasible? Cisco recommends avoiding the use of SVIs on the WLC side. Instead, it is best practice to configure the SVI on the core switch and use the ip helper-address command on that SVI.
In such a design, how can ARP spoofing attacks targeting wireless client devices be mitigated?"

https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/technical-reference/c9800-best-practices.html#DHCPbridgingandDHCPrelay

Thanks

2 Replies 2

Saikat Nandy
Cisco Employee
Cisco Employee

You can enable ARP Proxy inside the Policy Profile >> Advanced tab.

Rich R
VIP
VIP

And in fact ARP proxy is generally recommended best practice.
https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/technical-reference/c9800-best-practices.html#AddressResolutionProtocolARPproxy

Review Cisco Networking for a $25 gift card