AdvancedPublished 2026-07-04
Dynamic ARP Inspection — Validation Checks
Bundle lab
Harden Dynamic ARP Inspection (DAI) on an access switch by enabling additional packet validation checks: source MAC, destination MAC, and IP sanity. The uplink toward the DHCP server/gateway is trusted, access ports are untrusted. DHCP Snooping and baseline DAI are already enabled for VLAN 10; your task is to add the global DAI validation knobs and verify the change deterministically via show commands.
Learning objectives
- Explain how DAI leverages the DHCP Snooping binding table to verify ARP packets.
- Enable additional DAI validation checks (source MAC, destination MAC, and IP) to catch malformed or forged ARP frames.
- Verify DAI configuration and validation policy with show commands.
- Differentiate trusted vs. untrusted ports at the access edge and keep the trust boundary on the uplink.
Troubleshooting focus
- If legitimate ARP packets are dropped, verify the uplink toward the DHCP server/gateway is trusted for both DHCP Snooping and DAI.
- Confirm DHCP Snooping is enabled globally and for VLAN 10 so the DAI binding table can populate deterministically from config intent.
- Check that only the uplink is trusted; access ports must remain untrusted to prevent rogue DHCP/ARP sources.
- Review the DAI validation policy; enabling src-mac/dst-mac/ip will drop malformed frames that may appear during host boot or mis-cabling.
- Ensure host access ports are in the correct VLAN and the trunk carries VLAN 10 to the router-on-a-stick gateway.
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.