DAI and static addresses

Answered Question
Apr 22nd, 2009

All,

Say I have a core switch at 192.168.100.5, and I have a user add another switch on the network at their desk that's also addressed at 192.168.100.5. Is the best way to handle the situation by using dynamic arp inspection to shut down the port, or is dhcp snooping the best way?

We want to avoid having someone bring our core down. :)

Thanks,

John

I have this problem too.
0 votes
Correct Answer by Edison Ortiz about 7 years 9 months ago

You implement DAI along with ip arp inspection filter http://www.cisco.com/en/US/docs/ios/ipaddr/command/reference/iad_arp.html#wp1012267 for static IP assignment

and DAI with DHCP snooping for dynamic IP assignment.

More reading material

http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/configuration/guide/dynarp.html#wpmkr1047165

__

Edison.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.

Actions

This Discussion