Hey Guys,
I understand the differences between IP Source guard and Dynamic Arp
Inspection. One looks at IP packets and one looks at arp packets. But if we
had DHCP snooping configured and DAI configured, do we really need IPSG?
Lets say on a port configured with DHCP snooping and DAI only,
On 03/13/2012 07:24 AM, Shanawaz Batcha wrote:
because he doesnot send any DHCP packets. But Dynamic arp inspection will
catch him because he cannot do any ARP replies. And other machines will
require his arp reply to communicate to him. So static or spoofed IP
addresses will fail.
Then I am
Hello
The main difference is:
- IP Source Guard validate all packets regarding to source mac address, ip
address and source port
- Dynamic ARP Inspection inspects only ARP packets
More information about configuring that features you can find on page
On May 19, 2009, at 4:41 AM, Charuntorn Baimoung wrote:
What is different between IPSG and DAI? How I implemnet in same
interface config ?
http://www.ciscopress.com/articles/article.asp?p=1181682seqNum=7
http://www.ciscopress.com/articles/article.asp?p=1181682seqNum=8
What is different between IPSG and DAI? How I implemnet in same
interface config ?
___
cisco-nsp mailing list cisco-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/