cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
801
Views
0
Helpful
1
Replies

DHCP Snooping and Dynamic ARP Inspection

enaforhmd
Level 1
Level 1

Hi,

In order to reduce the impact of ARP spoofing attacks, I would like implement DHCP snooping and dynamic Arp inspection feature features on our Cisco enterprise network.

Test were conclusive for all devices connected directly to cisco switches.

However, I still have problems with devices connected to SOHO unmanaged switches.

Could you indicate me please, how I can overcome this problem.

You can find in attachment an example diagram.

Printer1 and PC2 cause connectivity problem when port Fa0/23 on switch S2 is configured as untrusted.

When I configure that port as trusted, I still can operate successfull ARP spoofing attacks with Cain & Abel software.

Best Regards,

Mustapha

1 Reply 1

Giuseppe Larosa
Hall of Fame
Hall of Fame

Hello Mustapha,

indeed DHCP snooping and DAI would fit with a design where no unmanaged switches are present so that a one-to-one corrispondence between MAC addresses of PCs and printers and ports can be done.

in your case you could just use port security with DHCP snooping trusted state as a way to mitigate at least MAC flood attacks.

Hope to help

Giuseppe

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card