SV-80565r1_rule
V-66075
SRG-NET-000362-L2S-000027
HFFS-L2-000016
CAT II
10
Configure the HP FlexFabric Switch to have Dynamic ARP Inspection (DAI) enabled on all user VLANs.
[HP-vlan2]arp detection enable
[HP-Ten-GigabitEthernet1/0/11]arp detection trust
Review the HP FlexFabric Switch configuration to verify that Dynamic ARP Inspection (DAI) feature is enabled on all user VLANs.
If DAI is not enabled on all user VLANs, this is a finding.
[HP]display arp detection
ARP detection is enabled in the following VLANs:
2
[HP]display arp detection statistics interface Ten-GigabitEthernet 1/0/11
State: U-Untrusted T-Trusted
ARP packets dropped by ARP inspect checking:
Interface(State) IP Src-MAC Dst-MAC Inspect
XGE1/0/11(T) 0 0 0 0
[HP]
V-66075
False
HFFS-L2-000016
Review the HP FlexFabric Switch configuration to verify that Dynamic ARP Inspection (DAI) feature is enabled on all user VLANs.
If DAI is not enabled on all user VLANs, this is a finding.
[HP]display arp detection
ARP detection is enabled in the following VLANs:
2
[HP]display arp detection statistics interface Ten-GigabitEthernet 1/0/11
State: U-Untrusted T-Trusted
ARP packets dropped by ARP inspect checking:
Interface(State) IP Src-MAC Dst-MAC Inspect
XGE1/0/11(T) 0 0 0 0
[HP]
M
2977