If Host 2 attempts to send an ARP request with the IP address 10.0.0.1, DAI drops the request and logs the following
system message:
00:18:08: %SW_DAI-4-DHCP_SNOOPING_DENY: 1 Invalid ARPs (Req) on Ethernet1/4, vlan
1.([0001.0001.0001/10.0.0.1/0000.0000.0000/0.0.0.0/01:53:21 UTC Fri Jan 23 2015])
The statistics display as follows:
switchB# show ip arp inspection statistics vlan 1
Vlan : 1
-----------
ARP Req Forwarded = 1
ARP Res Forwarded = 0
ARP Req Dropped = 1
ARP Res Dropped = 0
DHCP Drops = 1
DHCP Permits = 1
SMAC Fails-ARP Req = 0
SMAC Fails-ARP Res = 0
DMAC Fails-ARP Res = 0
IP Fails-ARP Req = 0
IP Fails-ARP Res = 0
switchB#
Additional References for DAI
Related Documents
Document TitleRelated Topic
Configuring IP ACLsACL TCAM regions
Configuring DHCP, on page 327DHCP and DHCP snooping
Standards
TitleStandard
An Ethernet Address Resolution Protocol (http://tools.ietf.org/html/rfc826)RFC-826
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
404
Configuring Dynamic ARP Inspection
Additional References for DAI