PrepAway - Latest Free Exam Questions & Answers

What does the global configuration command “ip arp inspection vlan 10-12,15” accomplish?

What does the global configuration command "ip arp inspection vlan 10-12,15" accomplish?

PrepAway - Latest Free Exam Questions & Answers

A.
Discards ARP packets with invalid IP-to-MAC address bindings on trusted ports

B.
Validates outgoing ARP requests for interfaces configured on VLAN 10, 11, 12, or 15

C.
Intercepts, logs, and discards ARP packets with invalid IP-to-MAC address bindings

D.
Intercepts all ARP requests and responses on trusted ports

Explanation:

The "ip arp inspection" command enables Dynamic ARP Inspection (DAI) for the specified VLANs. DAI is a security feature that validates Address Resolution Protocol (ARP) packets in a network. DAI allows a network administrator to intercept, log, and discard ARP packets with invalid MAC address to IP address bindings. This capability protects the network from certain "man-in-the-middle" attacks.
Reference:
http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.1/20ew/configuration/guide/dynarp.html


Leave a Reply