SV-220635r539671_rule
V-220635
SRG-NET-000362-L2S-000027
CISC-L2-000150
CAT II
10
Configure the switch to have DAI enabled on all user VLANs as shown in the example below:
SW2(config)#ip arp inspection vlan 2,4-8,11
Review the switch configuration to verify that the DAI feature is enabled on all user VLANs:
hostname SW2
…
…
…
ip arp inspection vlan 2,4-8,11
Note: DAI depends on the entries in the DHCP snooping binding database to verify IP-to-MAC address bindings in incoming ARP requests and ARP responses.
If DAI is not enabled on all user VLANs, this is a finding.
V-220635
False
CISC-L2-000150
Review the switch configuration to verify that the DAI feature is enabled on all user VLANs:
hostname SW2
…
…
…
ip arp inspection vlan 2,4-8,11
Note: DAI depends on the entries in the DHCP snooping binding database to verify IP-to-MAC address bindings in incoming ARP requests and ARP responses.
If DAI is not enabled on all user VLANs, this is a finding.
M
4070