Wednesday, April 3, 2019

Aruba 2930F - Dynamic ARP protection and incomplete DHCP-snooping binding table, will it work?

I'm in the process of hardening an 8 port 2930F and I'm unsure what the effect of ARP protection would be in this instance:

The switch currently has 6 Cicso phones attached to it and each phone has a laptop daisy chained from it. All phones and laptops are working fine and getting their DHCP addresses on their relevant VLANs.

If I look at the dhcp-snooping binding table, only one port is showing two devices (phone and laptop; an entry for each) with all other ports only showing the phone. (No idea why only one port is showing the complete picture).

If I enable ARP protection, considering that the dhcp binding table doesn't show the laptops, will it prevent ARP requests from reaching/leaving those laptops?

(Side quest: Is there a resolution to the fact that not all ports are showing the complete info as above?)

Many thanks



No comments:

Post a Comment