FAQ-After I Enable DAI or IPSG on an Interface, Why Can the Interface Still Forward Packets That Do Not Match the Binding Table

Publication Date:  2015-05-06 Views:  147 Downloads:  0
Issue Description
After I Enable DAI or IPSG on an Interface, Why Can the Interface Still Forward Packets That Do Not Match the Binding Table?
Solution
If the dhcp snooping trusted command is run on the interface, the interface considers all packets to be valid and forwards all packets regardless of whether Dynamic ARP Inspection (DAI) or IP Source Guard (IPSG) is configured.

END