282
NE2552E Application Guide for ENOS 8.4
DAI Configuration Guidelines and Restrictions
When
configuring
DAI,
follow
these
guidelines
and
restrictions:
DAI
is
an
ingress
security
feature;
it
does
not
perform
any
egress
checking.
DAI
is
not
effective
for
hosts
connected
to
switches
that
do
not
support
DAI
or
that
do
not
have
this
feature
enabled.
Because
man
‐
in
‐
the
‐
middle
attacks
are
limited
to
a
single
Layer
2
broadcast
domain,
separate
the
domain
with
DAI
checks
from
the
one
with
no
checking.
This
action
secures
the
ARP
caches
of
hosts
in
the
domain
enabled
for
DAI.
DAI
depends
on
the
entries
in
the
DHCP
snooping
binding
database
to
verify
IP
‐
to
‐
MAC
address
bindings
in
incoming
ARP
requests
and
ARP
responses.
For
non
‐
DHCP
environments,
for
each
static
IP
address
add
a
static
DHCP
Snooping
binding
entry
with
the
biggest
lease
time
in
order
not
to
expire.
Ports
belonging
to
a
port
‐
channel
must
have
the
same
trust
state.
DAI Configuration Example
Following
is
the
configuration
for
the
example
in
.
SwitchA(config)#
ip arp inspection vlan 2
SwitchA(config)#
interface port 1-2
SwitchA(config-if)#
ip arp inspection trust
SwitchA(config-if)#
exit
SwitchA(config)#
interface port 3
SwitchA(config-if)#
no ip arp inspection trust
SwitchA(config-if)#
exit
SwitchA(config)#
ip arp inspection vlan 2
SwitchB(config)# ip arp inspection vlan 2
SwitchB(config)# interface port 2
SwitchB(config-if)#
ip arp inspection trust
SwitchB(config-if)#
exit
SwitchB(config)# interface port 3
SwitchB(config-if)#
no ip arp inspection trust
SwitchB(config-if)#
exit
SwitchB(config)# ip arp inspection vlan 2
Summary of Contents for ThinkSystem NE2552E
Page 27: ... Copyright Lenovo 2018 27 Part 1 Getting Started ...
Page 28: ...28 NE2552E Application Guide for ENOS 8 4 ...
Page 70: ...70 NE2552E Application Guide for ENOS 8 4 ...
Page 85: ... Copyright Lenovo 2018 85 Part 2 Securing the Switch ...
Page 86: ...86 NE2552E Application Guide for ENOS 8 4 ...
Page 112: ...112 NE2552E Application Guide for ENOS 8 4 ...
Page 134: ...134 NE2552E Application Guide for ENOS 8 4 ...
Page 154: ...154 NE2552E Application Guide for ENOS 8 4 ...
Page 194: ...194 NE2552E Application Guide for ENOS 8 4 ...
Page 218: ...218 NE2552E Application Guide for ENOS 8 4 ...
Page 234: ...234 NE2552E Application Guide for ENOS 8 4 ...
Page 238: ...238 NE2552E Application Guide for ENOS 8 4 ...
Page 239: ... Copyright Lenovo 2018 239 Part 4 Advanced Switching Features ...
Page 240: ...240 NE2552E Application Guide for ENOS 8 4 ...
Page 242: ...242 NE2552E Application Guide for ENOS 8 4 ...
Page 278: ...278 NE2552E Application Guide for ENOS 8 4 ...
Page 284: ...284 NE2552E Application Guide for ENOS 8 4 ...
Page 314: ...314 NE2552E Application Guide for ENOS 8 4 ...
Page 338: ...338 NE2552E Application Guide for ENOS 8 4 ...
Page 374: ...374 NE2552E Application Guide for ENOS 8 4 ...
Page 388: ...388 NE2552E Application Guide for ENOS 8 4 ...
Page 418: ...418 NE2552E Application Guide for ENOS 8 4 ...
Page 430: ...430 NE2552E Application Guide for ENOS 8 4 ...
Page 432: ...432 NE2552E Application Guide for ENOS 8 4 ...
Page 436: ...436 NE2552E Application Guide for ENOS 8 4 ...
Page 460: ...460 NE2552E Application Guide for ENOS 8 4 ...
Page 461: ... Copyright Lenovo 2018 461 Part 7 Network Management ...
Page 462: ...462 NE2552E Application Guide for ENOS 8 4 ...
Page 476: ...476 NE2552E Application Guide for ENOS 8 4 ...
Page 498: ...498 NE2552E Application Guide for ENOS 8 4 ...
Page 520: ...520 NE2552E Application Guide for ENOS 8 4 ...
Page 534: ...534 NE2552E Application Guide for ENOS 8 4 ...
Page 536: ...536 NE2552E Application Guide for ENOS 8 4 ...
Page 544: ...544 NE2552E Application Guide for ENOS 8 4 ...
Page 549: ... Copyright Lenovo 2018 549 Part 9 Appendices ...
Page 550: ...550 NE2552E Application Guide for ENOS 8 4 ...
Page 566: ...566 NE2552E Application Guide for ENOS 8 4 ...
Page 572: ...572 NE2552E Application Guide for ENOS 8 4 ...
Page 573: ......
Page 574: ...Part Number 01KN246 Printed in USA IP P N 01KN246 ...