Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell EMC SmartFabric OS10 User Guide Release 10.5.0

Dynamic ARP inspection

Dynamic Address Resolution Protocol (ARP) Inspection (DAI) is a security feature that protects local area networks from man-in-the-middle ARP spoofing attacks.

When you enable DAI, the switch intercepts ARP packets on DAI-enabled VLANs. The switch then compares the source IP and source MAC addresses, VLAN, and the interface (physical or port channel) of the received packet with the DHCP snooping binding table. If the information in the packet does not match any entry in the DHCP snooping binding table, the switch drops the packet.

NOTE Dell EMC Networking recommends enabling DAI before enabling DHCP snooping on the system.

DAI violation logging

You can configure the system to log DAI validation failures corresponding to ARP packets. DAI violations are logged at the console if it is enabled. DAI violation logging is disabled by default.

If you configure an interface as trusted, the switch interprets ARP packets that ingress the interface from hosts as legitimate packets. By default, all interfaces are in DAI untrusted state.

For DAI to work, enable the DHCP snooping feature on the switch. DAI is disabled by default.

DAI statistics

The system maintains DAI statistics that contain the following details:

  • Valid ARP requests
  • Invalid ARP requests
  • Valid ARP replies
  • Invalid ARP replies

You can clear the DAI statistics using the clear ip arp inspection statistics command.

DAI trusted interfaces

By default, all ports are untrusted and all packets go through the DAI validation process on all DAI-enabled VLANs. You can configure an interface to bypass ARP inspection by configuring the interface as trusted.

NOTE Dell EMC Networking recommends configuring the arp inspection-trust command on the DHCP snooping trusted interfaces when DAI is enabled for a VLAN.

Restrictions for Dynamic ARP Inspection

  • Dynamic ARP Inspection with VxLAN bridges is not supported.
  • Maximum number of recommended Dynamic ARP Inspection entries is 2000.

Enable Dynamic ARP Inspection

  • Enable DHCP snooping. For more information about configuring DHCP snooping, see DHCP snooping.

  • Enable Dynamic ARP Inspection on a VLAN in INTERFACE VLAN mode.

    arp inspection

Enable Dynamic ARP Inspection violation logging

  • Use the following command in CONFIGURATION mode:

    arp inspection violation logging

Bypass Dynamic ARP Inspection on an interface

  • Use the following command in INTERFACE mode:

    arp inspection-trust

Clear DAI statistics

  • Clear DAI statistics in EXEC mode.

    clear ip arp inspection statistics [vlan vlan-name]

View DAI database

  • View DAI database in EXEC mode

    show ip arp inspection database [vlan vlan-name]

    Use the vlan option to view DAI database for a specific VLAN.

Example for viewing DAI database

OS10# show ip arp inspection database
Number of entries : 828
 
Address         Hardware Address        Interface           VLAN
--------------------------------------------------------------------
10.2.1.1       00:40:50:00:00:00       port-channel100     vlan3001
10.1.1.13      00:2a:10:01:00:00       port-channel100     vlan3001
10.1.1.62      00:2a:10:01:00:01       port-channel100     vlan3001 

View DAI statistics

You can view valid and invalid ARP requests that the switch has received and replies that the switch has sent.

  • Use the following command in EXEC mode:

    show ip arp inspection statistics vlan vlan-name

    Example for viewing DAI statistics

    OS10# show ip arp inspection statistics                              
    Dynamic ARP Inspection (DAI) Statistics
    ---------------------------------------
    
    Valid ARP Requests           : 0
    Valid ARP Replies            : 1000
    Invalid ARP Requests         : 1000
    Invalid ARP Replies          : 0
    
  • View DAI violation information

    show ip arp inspection logging

    Example for viewing DAI violation information

    OS10# show ip arp inspection logging
    Total Number of Clients                         : 1
    New Clients learnt in current Interval          : 0
    Invalid ARP packets in current interval         : 0                                                                                
    Address       Hw-Address          Port           VLAN   First-detected-time   Packet-count   
    -----------------------------------------------------------------------------------
    10.1.1.1      12:d3:43:a1:2e:23   ethernet1/1/1  10     00:23:14              2

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\