DHCP Snooping and DAI

Understand and implement DHCP Snooping and Dynamic ARP Inspection to secure Layer 2 networks.

DHCP Snooping and Dynamic ARP Inspection

Securing the Layer 2 domain is crucial for preventing common local network attacks like rogue DHCP servers and ARP poisoning.

DHCP Snooping

DHCP Snooping prevents rogue DHCP servers from assigning IP addresses to clients. It works by designating switch ports as either Trusted or Untrusted.

  • Trusted Ports: Allowed to send DHCP server messages (like DHCP Offer and DHCP Ack). Typically connected to legitimate DHCP servers or uplinks.
  • Untrusted Ports: Only allowed to send client messages (like DHCP Discover and DHCP Request). All access ports should be untrusted.

DHCP Snooping also builds a binding database, mapping client MAC addresses to their assigned IP addresses, lease times, and physical switch ports.

Dynamic ARP Inspection (DAI)

DAI prevents ARP spoofing/poisoning attacks by intercepting, logging, and discarding ARP packets with invalid MAC-to-IP address bindings.

DAI relies on the DHCP Snooping binding database. When an ARP packet is received on an untrusted port, the switch checks the sender’s MAC and IP against the database. If they don’t match, the packet is dropped.

Like DHCP Snooping, DAI uses a concept of trusted and untrusted ports:

  • Trusted Ports: Bypass DAI checks (e.g., uplinks).
  • Untrusted Ports: Subject to DAI validation against the binding database.