
If Host 2 attempts to send an ARP request with the IP address 10.0.0.1, DAI drops the request and logs the following
system message:
00:18:08: %SW_DAI-4-DHCP_SNOOPING_DENY: 1 Invalid ARPs (Req) on Ethernet1/4, vlan
1.([0001.0001.0001/10.0.0.1/0000.0000.0000/0.0.0.0/01:53:21 UTC Fri Jan 23 2015])
The statistics display as follows:
switchB#
show ip arp inspection statistics vlan 1
Vlan : 1
-----------
ARP Req Forwarded
= 1
ARP Res Forwarded
= 0
ARP Req Dropped
= 1
ARP Res Dropped
= 0
DHCP Drops
= 1
DHCP Permits
= 1
SMAC Fails-ARP Req = 0
SMAC Fails-ARP Res = 0
DMAC Fails-ARP Res = 0
IP Fails-ARP Req
= 0
IP Fails-ARP Res
= 0
switchB#
Additional References for DAI
Related Documents
Document Title
Related Topic
ACL TCAM regions
DHCP and DHCP snooping
Standards
Title
Standard
An Ethernet Address Resolution Protocol (
http://tools.ietf.org/html/rfc826
)
RFC-826
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
404
Configuring Dynamic ARP Inspection
Additional References for DAI