SV-110347r1_rule
V-101243
SRG-NET-000362-L2S-000027
CISC-L2-000150
CAT II
10
Configure the switch to have Dynamic Address Resolution Protocol (ARP) Inspection (DAI) enabled on all user VLANs as shown in the example below:
SW1(config)# ip arp inspection vlan 2,4-8,11
Review the switch configuration to verify that Dynamic Address Resolution Protocol (ARP) Inspection (DAI) feature is enabled on all user VLANs.
hostname SW2
…
…
…
ip arp inspection vlan 2,4-8,11
Note: DAI depends on the entries in the DHCP snooping binding database to verify IP-to-MAC address bindings in incoming ARP requests and ARP responses.
If DAI is not enabled on all user VLANs, this is a finding.
V-101243
False
CISC-L2-000150
Review the switch configuration to verify that Dynamic Address Resolution Protocol (ARP) Inspection (DAI) feature is enabled on all user VLANs.
hostname SW2
…
…
…
ip arp inspection vlan 2,4-8,11
Note: DAI depends on the entries in the DHCP snooping binding database to verify IP-to-MAC address bindings in incoming ARP requests and ARP responses.
If DAI is not enabled on all user VLANs, this is a finding.
M
3551