Why ARP is easy to fool
ARP has no authentication. Hosts accept ARP replies, and often even unsolicited ones, and update their caches. So anyone on the LAN can claim to be any IP address.
ARP spoofing: a man in the middle
Situation: an attacker on the same VLAN wants to read PC A's traffic to the internet.
- 1. Poison the victim. The attacker sends PC A forged ARP replies saying the gateway's IP belongs to the attacker's MAC.
- 2. Poison the gateway. And tells the gateway that PC A's IP is at the attacker's MAC.
- 3. Traffic detours. PC A's internet traffic now goes to the attacker first…
- 4. …and is passed on. The attacker forwards it so nothing seems wrong, while reading or changing it.
The defence: Dynamic ARP Inspection
Dynamic ARP Inspection (DAI) on the switch checks every ARP packet arriving on an untrusted port against the DHCP snooping binding table, the switch's record of which IP was leased to which MAC on which port. An ARP claim that doesn't match is dropped.
- 1. Forged reply arrives. It comes in on untrusted port Gi1/0/5.
- 2. Checked and dropped. The binding table says Gi1/0/5 leased 192.168.10.66, not 192.168.10.1, so the packet is discarded and logged.
- 3. Legitimate ARP still works. PC A's own ARP matches its DHCP binding, and the gateway's port is trusted, so normal resolution is unaffected.
- Trusted ports (uplinks to other switches and routers) aren't checked.
- Hosts with static IPs have no DHCP binding, so they need an ARP ACL or they'll be blocked.
- Rate limiting: untrusted ports allow 15 ARP packets per second by default; more and the port is err-disabled, which stops ARP floods.
Configure
⚠️ Based on Cisco IOS / IOS XE documentation, not run in a lab here. Enable DHCP snooping first and let bindings build, or legitimate hosts will be blocked.
ip dhcp snooping
ip dhcp snooping vlan 10
ip arp inspection vlan 10
interface GigabitEthernet1/0/24
description Uplink to gateway
ip dhcp snooping trust
ip arp inspection trustVerify
show ip dhcp snooping bindingThe MAC, IP, VLAN and port of every DHCP lease the switch has seen: the reference DAI checks against.
SW1#show ip arp inspection statistics vlan 10 Vlan Forwarded Dropped DHCP Drops ACL Drops ---- --------- ------- ---------- --------- 10 1532 41 41 0
Check yourself
What does Dynamic ARP Inspection compare ARP packets against?
After enabling DAI, a printer with a static IP can't be reached. Why?