Configuring Dynamic ARP Inspection
D-Link
Unified Wired and Wireless Access System
Oct. 2015
Page 274
D-Link UWS User Manual
Configuring Dynamic ARP Inspection
Dynamic ARP Inspection (DAI) is a security feature that rejects invalid and malicious ARP packets. DAI prevents
a class of man-in-the-middle attacks, where an unfriendly station intercepts traffic for other stations by
poisoning the ARP caches of its unsuspecting neighbors. The miscreant sends ARP requests or responses
mapping another station’s IP address to its own MAC address.
DAI relies on DHCP snooping. DHCP snooping listens to DHCP message exchanges and builds a binding
database of valid {MAC address, IP address, VLAN, and interface} tuples.
When DAI is enabled, the switch drops ARP packets whose sender MAC address and sender IP address do not
match an entry in the DHCP snooping bindings database. You can optionally configure additional ARP packet
validation.
DAI Configuration
Use the DAI Configuration page to configure global DAI settings.
To display the DAI Configuration page, click
LAN > L2 Features
>
Dynamic ARP Inspection > DAI Configuration
in the navigation tree.
Figure 171: Dynamic ARP Inspection Configuration
• Click
Submit
to apply the new configuration and cause the change to take effect. These changes will not
be retained across a power cycle unless a Save configuration is performed.
Table 154: Dynamic ARP Inspection Configuration
Field
Description
Validate Source
MAC
Select the DAI Source MAC Validation Mode for the switch. If you select
Enable
, Sender
MAC validation for the ARP packets will be enabled. The default is
Disable
.
Validate
Destination MAC
Select the DAI Destination MAC Validation Mode for the switch. If you select
Enable
,
Destination MAC validation for the ARP Response packets will be enabled. The default is
Disable.
Validate IP
Select the DAI IP Validation Mode for the switch. If you select
Enable
, IP Address validation
for the ARP packets will be enabled. The default is
Disable.
Summary of Contents for DWL-8600AP
Page 754: ......