
2-78
Cisco ME 3400E, ME 3400, and ME 2400 Ethernet Access Switch System Message Guide
OL-9641-04
Chapter 2 Messages and Recovery Procedures
SW_DAI Messages
SW_DAI Messages
This section contains the dynamic ARP inspection (DAI) messages.
Note
These messages apply only to the Cisco ME 3400E and ME 3400 switches.
Error Message
SW_DAI-4-ACL_DENY: [dec] Invalid ARPs ([chars]) on [chars], vlan
[dec].([[enet]/[chars]/[enet]/[chars]/[time-of-day]]).
Explanation
This message means that the switch has received ARP packets considered invalid by
ARP inspection. The packets are erroneous, and their presence shows that administratively denied
packets were seen in the network. This log message appears when ACLs either explicitly or
implicitly deny packets (with static ACL configuration). These packets show attempted
man-in-the-middle attacks in the network. The first [dec] is the number of invalid ARP packets. The
first [chars] is either Req (request) or Res (response), and the second [chars] is the short name of the
ingress interface. The second [dec] is the ingress VLAN ID.
[enet]/[chars]/[enet]/[chars]/[time-of-day] is the MAC address of the sender, the IP address of the
sender, the MAC address of the target, the IP address of the target, and the time of day.
Recommended Action
No action is required.
Error Message
SW_DAI-4-DHCP_SNOOPING_DENY: [dec] Invalid ARPs ([chars]) on [chars],
vlan [dec].([[enet]/[chars]/[enet]/[chars]/[time-of-day]]).
Explanation
This message means that the switch has received ARP packets considered invalid by
ARP inspection. The packets are erroneous, and their presence might show attempted
man-in-the-middle attacks in the network. This log message appears when the sender’s IP and MAC
address binding for the received VLAN is not in the DHCP snooping database. The first [dec] is the
number of invalid ARP packets. The first [chars] is either Req (request) or Res (response), and the
second [chars] is the short name of the ingress interface. The second [dec] is the ingress VLAN ID.
[enet]/[chars]/[enet]/[chars]/[time-of-day] is the MAC address of the sender, the IP address of the
sender, the MAC address of the target, the IP address of the target, and the time of day.
Recommended Action
No action is required.
Error Message
SW_DAI-6-DHCP_SNOOPING_PERMIT: [dec] ARPs ([chars]) on [chars], vlan
[dec].([[enet]/[chars]/[enet]/[chars]/[time-of-day]]).
Explanation
This message means that the switch has received ARP packets that have been permitted
because the sender’s IP and MAC address match the DHCP snooping database for the received
VLAN. The first [dec] is the number of valid ARP packets. The first [chars] is either Req (request)
or Res (response), and the second [chars] is the short name of the ingress interface. The second [dec]
is the ingress VLAN ID. [enet]/[chars]/[enet]/[chars]/[time-of-day] is the MAC address of the
sender, the IP address of the sender, the MAC address of the target, the IP address of the target, and
the time of day.
Recommended Action
No action is required.