Routelearn.net
Course menu

Course 13: Security FundamentalsLesson 1.3 (3 of 8 in this course)81 of 91 in the CCNA series

ARP security

ARP spoofing and man-in-the-middle attacks, and how Dynamic ARP Inspection stops them.

Intermediate · 8 min read

DAI (Dynamic ARP Inspection) is a switch security feature that checks ARP packets received on untrusted ports against the DHCP snooping binding table, or an ARP ACL, and drops those whose IP-to-MAC mapping does not match. It prevents ARP spoofing attacks such as man-in-the-middle and gateway impersonation.

In simple terms: ARP believes whatever it is told, so an attacker can lie “I am the gateway.” DAI makes the switch check every ARP message against its records and throw away the lies.

Why ARP is easy to fool

ARP has no authentication. Hosts accept ARP replies, and often even unsolicited ones, and update their caches. So anyone on the LAN can claim to be any IP address.

ARP spoofing: a man in the middle

Situation: an attacker on the same VLAN wants to read PC A's traffic to the internet.

SwitchPC A192.168.10.20Gateway192.168.10.1maliciousAttacker192.168.10.66
  1. 1. Poison the victim. The attacker sends PC A forged ARP replies saying the gateway's IP belongs to the attacker's MAC.
  2. 2. Poison the gateway. And tells the gateway that PC A's IP is at the attacker's MAC.
  3. 3. Traffic detours. PC A's internet traffic now goes to the attacker first…
  4. 4. …and is passed on. The attacker forwards it so nothing seems wrong, while reading or changing it.

The defence: Dynamic ARP Inspection

Dynamic ARP Inspection (DAI) on the switch checks every ARP packet arriving on an untrusted port against the DHCP snooping binding table, the switch's record of which IP was leased to which MAC on which port. An ARP claim that doesn't match is dropped.

SwitchDAI on VLAN 10PC AuntrustedGatewaytrusted uplinkmaliciousAttackeruntrusted · Gi1/0/5
  1. 1. Forged reply arrives. It comes in on untrusted port Gi1/0/5.
  2. 2. Checked and dropped. The binding table says Gi1/0/5 leased 192.168.10.66, not 192.168.10.1, so the packet is discarded and logged.
  3. 3. Legitimate ARP still works. PC A's own ARP matches its DHCP binding, and the gateway's port is trusted, so normal resolution is unaffected.
  • Trusted ports (uplinks to other switches and routers) aren't checked.
  • Hosts with static IPs have no DHCP binding, so they need an ARP ACL or they'll be blocked.
  • Rate limiting: untrusted ports allow 15 ARP packets per second by default; more and the port is err-disabled, which stops ARP floods.

Configure

⚠️ Based on Cisco IOS / IOS XE documentation, not run in a lab here. Enable DHCP snooping first and let bindings build, or legitimate hosts will be blocked.

ip dhcp snooping ip dhcp snooping vlan 10 ip arp inspection vlan 10 interface GigabitEthernet1/0/24 description Uplink to gateway ip dhcp snooping trust ip arp inspection trust

Verify

show ip dhcp snooping binding

The MAC, IP, VLAN and port of every DHCP lease the switch has seen: the reference DAI checks against.

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show ip arp inspection statistics vlan 10
 Vlan      Forwarded        Dropped     DHCP Drops      ACL Drops
 ----      ---------        -------     ----------      ---------
   10           1532             41             41              0
DHCP Drops counts ARP packets rejected because they didn't match a binding. A rising number on one VLAN is worth investigating: find the port in the logs.

Check yourself

Predict · scenario 1

What does Dynamic ARP Inspection compare ARP packets against?

Predict · scenario 2

After enabling DAI, a printer with a static IP can't be reached. Why?