© Copyright Lenovo 2018
Chapter 18: Dynamic ARP Inspection
281
Figure 30.
ARP
Packet
Validation
on
a
VLAN
Enabled
for
DAI
If
Switch
A
is
not
running
DAI,
Host
1
can
easily
poison
the
ARP
caches
of
Switch
B
and
Host
2,
if
the
link
between
the
switches
is
configured
as
trusted.
This
condition
can
occur
even
though
Switch
B
is
running
DAI.
The
best
option
for
the
setup
from
is
to
have
DAI
running
on
both
switches
and
to
have
the
link
between
the
switches
configured
as
trusted.
In
cases
in
which
some
switches
in
a
VLAN
run
DAI
and
other
switches
do
not,
configure
the
interfaces
connecting
such
switches
as
untrusted.
However,
to
validate
the
bindings
of
packets
from
switches
where
DAI
is
not
configured,
configure
static
DHCP
snooping
binding
entries
on
the
switch
running
DAI.
When
you
cannot
determine
such
bindings,
isolate
switches
running
DAI
at
Layer
3
from
switches
not
running
DAI.
DAI
ensures
that
hosts
(on
untrusted
interfaces)
connected
to
a
switch
running
DAI
do
not
poison
the
ARP
caches
of
other
hosts
in
the
network.
However,
DAI
does
not
prevent
hosts
in
other
portions
of
the
network
connected
through
a
trusted
interface
from
poisoning
the
caches
of
the
hosts
that
are
connected
to
a
switch
running
DAI.
DHCP server
Port 1
Port 1
Switch A
Switch B
Port 2
Port 2
Port 3
Port 3
Host 1
Host 2
Summary of Contents for ThinkSystem NE2552E
Page 27: ... Copyright Lenovo 2018 27 Part 1 Getting Started ...
Page 28: ...28 NE2552E Application Guide for ENOS 8 4 ...
Page 70: ...70 NE2552E Application Guide for ENOS 8 4 ...
Page 85: ... Copyright Lenovo 2018 85 Part 2 Securing the Switch ...
Page 86: ...86 NE2552E Application Guide for ENOS 8 4 ...
Page 112: ...112 NE2552E Application Guide for ENOS 8 4 ...
Page 134: ...134 NE2552E Application Guide for ENOS 8 4 ...
Page 154: ...154 NE2552E Application Guide for ENOS 8 4 ...
Page 194: ...194 NE2552E Application Guide for ENOS 8 4 ...
Page 218: ...218 NE2552E Application Guide for ENOS 8 4 ...
Page 234: ...234 NE2552E Application Guide for ENOS 8 4 ...
Page 238: ...238 NE2552E Application Guide for ENOS 8 4 ...
Page 239: ... Copyright Lenovo 2018 239 Part 4 Advanced Switching Features ...
Page 240: ...240 NE2552E Application Guide for ENOS 8 4 ...
Page 242: ...242 NE2552E Application Guide for ENOS 8 4 ...
Page 278: ...278 NE2552E Application Guide for ENOS 8 4 ...
Page 284: ...284 NE2552E Application Guide for ENOS 8 4 ...
Page 314: ...314 NE2552E Application Guide for ENOS 8 4 ...
Page 338: ...338 NE2552E Application Guide for ENOS 8 4 ...
Page 374: ...374 NE2552E Application Guide for ENOS 8 4 ...
Page 388: ...388 NE2552E Application Guide for ENOS 8 4 ...
Page 418: ...418 NE2552E Application Guide for ENOS 8 4 ...
Page 430: ...430 NE2552E Application Guide for ENOS 8 4 ...
Page 432: ...432 NE2552E Application Guide for ENOS 8 4 ...
Page 436: ...436 NE2552E Application Guide for ENOS 8 4 ...
Page 460: ...460 NE2552E Application Guide for ENOS 8 4 ...
Page 461: ... Copyright Lenovo 2018 461 Part 7 Network Management ...
Page 462: ...462 NE2552E Application Guide for ENOS 8 4 ...
Page 476: ...476 NE2552E Application Guide for ENOS 8 4 ...
Page 498: ...498 NE2552E Application Guide for ENOS 8 4 ...
Page 520: ...520 NE2552E Application Guide for ENOS 8 4 ...
Page 534: ...534 NE2552E Application Guide for ENOS 8 4 ...
Page 536: ...536 NE2552E Application Guide for ENOS 8 4 ...
Page 544: ...544 NE2552E Application Guide for ENOS 8 4 ...
Page 549: ... Copyright Lenovo 2018 549 Part 9 Appendices ...
Page 550: ...550 NE2552E Application Guide for ENOS 8 4 ...
Page 566: ...566 NE2552E Application Guide for ENOS 8 4 ...
Page 572: ...572 NE2552E Application Guide for ENOS 8 4 ...
Page 573: ......
Page 574: ...Part Number 01KN246 Printed in USA IP P N 01KN246 ...