SV-220661r539671_rule
V-220661
SRG-NET-000362-L2S-000027
CISC-L2-000150
CAT II
10
Configure the switch to have Dynamic Address Resolution Protocol (ARP) Inspection (DAI) enabled on all user VLANs as shown in the example below:
SW2(config)#ip arp inspection vlan 2,4-8,11
Review the switch configuration to verify that Dynamic Address Resolution Protocol (ARP) Inspection (DAI) feature is enabled on all user VLANs.
hostname SW2
…
…
…
ip arp inspection vlan 2,4-8,11
Note: DAI depends on the entries in the DHCP snooping binding database to verify IP-to-MAC address bindings in incoming ARP requests and ARP responses.
If DAI is not enabled on all user VLANs, this is a finding.
V-220661
False
CISC-L2-000150
Review the switch configuration to verify that Dynamic Address Resolution Protocol (ARP) Inspection (DAI) feature is enabled on all user VLANs.
hostname SW2
…
…
…
ip arp inspection vlan 2,4-8,11
Note: DAI depends on the entries in the DHCP snooping binding database to verify IP-to-MAC address bindings in incoming ARP requests and ARP responses.
If DAI is not enabled on all user VLANs, this is a finding.
M
4071