2-112
Catalyst 3750-X, 3750-E, 3560-X, and 3560-E Switch System Message Guide
OL-9772-05
Chapter 2 Message and Recovery Procedures
SW_DAI Messages
SW_DAI Messages
Error Message
SW_DAI-4-ACL_DENY: [dec] Invalid ARPs ([chars]) on [chars], vlan
[dec].([[enet]/[chars]/[enet]/[chars]/[time-of-day]]).
Explanation
The switch has received ARP packets considered invalid by ARP inspection. The
packets are erroneous, and their presence shows that administratively denied packets were seen in
the network. This log message appears when packets have been denied by ACLs either explicitly or
implicitly (with static ACL configuration). These packets show attempted man-in-the-middle
attacks in the network. The first [dec] is the number of invalid ARP packets. The first [chars] is either
Req (request) or Res (response), and the second [chars] is the short name of the ingress interface.
The second [dec] is the ingress VLAN ID. [enet]/[chars]/[enet]/[chars]/
[time-of-day] is the MAC address of the sender, the IP address of the sender, the MAC address of
the target, the IP address of the target, and the time of day.
Recommended Action
No action is required.
Error Message
SW_DAI-4-DHCP_SNOOPING_DENY: [dec] Invalid ARPs ([chars]) on [chars],
vlan [dec].([[enet]/[chars]/[enet]/[chars]/[time-of-day]]).
Explanation
The switch has received ARP packets considered invalid by ARP inspection. The
packets are erroneous, and their presence might show attempted man-in-the-middle attacks in the
network. This log message appears when the IP and MAC address binding of the sender for the
received VLAN is not present in the DHCP snooping database. The first [dec] is the number of
invalid ARP packets. The first [chars] is either Req (request) or Res (response), and the second
[chars] is the short name of the ingress interface. The second [dec] is the ingress VLAN ID.
[enet]/[chars]/[enet]/[chars]/[time-of-day] is the MAC address of the sender, the IP address of the
sender, the MAC address of the target, the IP address of the target, and the time of day.
Recommended Action
No action is required.
Error Message
SW_DAI-6-DHCP_SNOOPING_PERMIT: [dec] ARPs ([chars]) on [chars], vlan
[dec].([[enet]/[chars]/[enet]/[chars]/[time-of-day]]).
Explanation
The switch has received ARP packets that have been permitted because the IP and MAC
address of the sender match the DHCP snooping database for the received VLAN. The first [dec] is
the number of valid ARP packets. The first [chars] is either Req (request) or Res (response), and the
second [chars] is the short name of the ingress interface. The second [dec] is the ingress VLAN ID.
[enet]/[chars]/[enet]/[chars]/[time-of-day] is the MAC address of the sender, the IP address of the
sender, the MAC address of the target, the IP address of the target, and the time of day.
Recommended Action
No action is required.
Error Message
SW_DAI-4-INVALID_ARP: [dec] Invalid ARPs ([chars]) on [chars], vlan
[dec].([[enet]/[chars]/[enet]/[chars]/[time-of-day]]).
Explanation
The switch has received ARP packets considered invalid by ARP inspection. The
packets do not pass one or more validation checks of the source or destination MAC address or the
IP address. The first [dec] is the number of invalid ARP packets. The first [chars] is either Req
(request), Res (response), or Invalid Opcode. The second [chars] is the short name of the ingress
Summary of Contents for Catalyst 3560-E Series
Page 6: ...Contents vi Catalyst 3750 X 3750 E 3560 X and 3560 E Switch System Message Guide OL 9772 05 ...
Page 10: ...x Catalyst 3750 X 3750 E 3560 X and 3560 E Switch System Message Guide OL 9772 05 Preface ...
Page 150: ...Index IN 6 Catalyst 3750 X 3750 E 3560 X and 3560 E Switch System Message Guide OL 9772 05 ...