DAI and static addresses

Answered Question
Apr 22nd, 2009
User Badges:
  • Purple, 4500 points or more

All,


Say I have a core switch at 192.168.100.5, and I have a user add another switch on the network at their desk that's also addressed at 192.168.100.5. Is the best way to handle the situation by using dynamic arp inspection to shut down the port, or is dhcp snooping the best way?


We want to avoid having someone bring our core down. :)



Thanks,

John

Correct Answer by Edison Ortiz about 8 years 1 month ago

You implement DAI along with ip arp inspection filter http://www.cisco.com/en/US/docs/ios/ipaddr/command/reference/iad_arp.html#wp1012267 for static IP assignment


and DAI with DHCP snooping for dynamic IP assignment.


More reading material


http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/configuration/guide/dynarp.html#wpmkr1047165


__


Edison.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
Edison Ortiz Wed, 04/22/2009 - 15:35
User Badges:
  • Super Bronze, 10000 points or more
  • Hall of Fame,

    Founding Member

You implement DAI along with ip arp inspection filter http://www.cisco.com/en/US/docs/ios/ipaddr/command/reference/iad_arp.html#wp1012267 for static IP assignment


and DAI with DHCP snooping for dynamic IP assignment.


More reading material


http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/configuration/guide/dynarp.html#wpmkr1047165


__


Edison.

Actions

This Discussion