ARP and DHCP Snoop Entries

DAI uses the IP-to-MAC mappings in the ARP table to validate ARP packets received on untrusted ports. DAI relies on the following entries:

  • Dynamic ARP: Normal ARP learned from trusted ports.
  • Static ARP: Statically configured IP address, MAC address, and port mapping.
  • Inspection ARP: Statically configured IP-to-MAC mapping, where the port is initially unspecified. The actual physical port mapping will be resolved and updated from validated ARP packets. Refer to Configuring an Inspection ARP Entry.
  • DHCP-Snooping ARP: Information collected from snooping DHCP packets when DHCP snooping is enabled on VLANs. DHCP snooping entries are stored in a different table and are not part of the ARP table.

The status of an ARP entry is either pending or valid:

  • Valid: The mapping is valid, and the port is resolved. This is always the case for static ARP entries.
  • Pending: For normal dynamic ARP entries before they are resolved, and the port is mapped. Their status changes to valid when they are resolved, and the port is mapped.

Refer to "System reboot and the binding database" in the RUCKUS FastIron DHCP Configuration Guide.