• You must configure the ACL TCAM region size for DAI using the
hardware access-list tcam region
arp-ether
command. The DAI configuration will not be accepted unless the arp-ether region is effective.
See
Configuring ACL TCAM Region Sizes, on page 240
.
Guidelines and Limitations for DAI
DAI has the following configuration guidelines and limitations:
• DAI is an ingress security feature; it does not perform any egress checking.
• DAI is not effective for hosts connected to devices that do not support DAI or that do not have this feature
enabled. Because man-in-the-middle attacks are limited to a single Layer 2 broadcast domain, you should
separate the domain with DAI from domains without DAI. This separation secures the ARP caches of
hosts in the domain with DAI.
• When you use the
feature dhcp
command to enable the DHCP feature, there is a delay of approximately
30 seconds before the I/O modules receive the DHCP or DAI configuration. This delay occurs regardless
of the method that you use to change from a configuration with the DHCP feature disabled to a
configuration with the DHCP feature enabled. For example, if you use the rollback feature to revert to
a configuration that enables the DHCP feature, the I/O modules receive the DHCP and DAI configuration
approximately 30 seconds after you complete the rollback.
• DAI is supported on access ports, trunk ports, and port-channel ports.
• The DAI trust configuration of a port channel determines the trust state of all physical ports that you
assign to the port channel. For example, if you have configured a physical port as a trusted interface and
then you add that physical port to a port channel that is an untrusted interface, the physical port becomes
untrusted.
• When you remove a physical port from a port channel, the physical port does not retain the DAI trust
state configuration of the port channel.
• When you change the trust state on the port channel, the device onfigures a new trust state on all the
physical ports that comprise the channel.
• If you want DAI to use static IP-MAC address bindings to determine if ARP packets are valid, make
sure that you have configured the static IP-MAC address bindings.
• If you want DAI to use dynamic IP-MAC address bindings to determine if ARP packets are valid, make
sure that DHCP snooping is enabled.
• ARP ACLs are not supported.
Default Settings for DAI
This table lists the default settings for DAI parameters.
Table 33: Default DAI Parameters
Default
Parameters
Disabled on all VLANs.
DAI
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
393
Configuring Dynamic ARP Inspection
Guidelines and Limitations for DAI