An administrator has enabled Dynamic ARP Inspection (DAI) on all access switches, using DHCP snooping bindings for validation. Several servers use statically configured IP addresses and never send DHCP requests, so their legitimate ARP replies are now being dropped by DAI. What should the administrator configure to permit these servers' ARP traffic while keeping DAI enforced for all DHCP clients?
- ADisable DHCP snooping on the VLAN containing the servers
- BConfigure 'ip arp inspection validate src-mac dst-mac ip' globally
- CConfigure the server switchports as DAI trusted interfaces
- DCreate an ARP ACL that maps each server's static IP to its MAC address and apply it to the DAI configuration
Show answer & explanationAnswer & explanation
Correct answer: D. Create an ARP ACL that maps each server's static IP to its MAC address and apply it to the DAI configuration
Since DAI validates ARP packets against the DHCP snooping binding table, hosts with static IPs (never seen by DHCP snooping) will fail validation. An ARP ACL manually defines valid IP-to-MAC mappings for these static hosts and can be applied to DAI so their traffic is permitted, while DHCP clients are still validated dynamically against the snooping database.
Why the other options are wrong
- A. Disabling DHCP snooping would break DAI validation entirely for that VLAN, not just fix the static host issue.
- B. This changes what fields DAI validates but does not solve the missing binding entries for static hosts.
- C. Trusting the ports would bypass DAI inspection entirely for those ports, reducing security more than necessary.
DAI ARP ACLs for Static Hosts
An ARP access control list can be configured to manually define valid IP-to-MAC bindings for static IP hosts, allowing DAI to validate them without relying on the DHCP snooping binding table.
- Used when hosts don't use DHCP (e.g., servers, printers)
- Applied with 'ip arp inspection filter <acl-name> vlan <id>'
- DHCP clients still validated against snooping bindings normally
Memory trick: Static hosts need a static list — the ARP ACL fills the gap DHCP snooping can't.