Techerest

ARP, ARP Spoofing และ Dynamic ARP Inspection (DAI) บน Cisco Switch คืออะไร?

หลังจากเข้าใจ DHCP Snooping และการสร้าง DHCP Snooping Binding Table แล้ว Security Feature ที่ควรเรียนต่อทันทีคือ Dynamic ARP Inspection หรือ DAI ซึ่งช่วยตรวจสอบ ARP Traffic และลดความเสี่ยงจาก ARP Spoofing / ARP Poisoning ภายใน Layer 2 Network

ก่อนเข้าใจ DAI จำเป็นต้องเข้าใจก่อนว่า ARP — Address Resolution Protocol ทำหน้าที่อะไร เหตุใดคอมพิวเตอร์ต้องรู้ทั้ง IP Address และ MAC Address และเหตุใดการปลอม ARP Information จึงสามารถสร้างปัญหาด้าน Network Security ได้

บทความนี้จะเริ่มจากพื้นฐาน ARP, ARP Request, ARP Reply และ ARP Table จากนั้นอธิบายแนวคิด ARP Spoofing ก่อนต่อยอดไปยัง Dynamic ARP Inspection บน Cisco Switch พร้อม Configuration, Verification, Troubleshooting และ Lab

ภาค 1: ทำความเข้าใจ ARP

ARP คืออะไร?

ARP — Address Resolution Protocol เป็น Protocol ที่ใช้ใน IPv4 Network เพื่อค้นหาความสัมพันธ์ระหว่าง IPv4 Address กับ Layer 2 Address เช่น Ethernet MAC Address บน Local Link

ตัวอย่าง:

PC-A

IP Address
192.168.10.10

ต้องการส่งข้อมูลไปยัง

192.168.10.20

แต่ Ethernet Frame
ต้องมี Destination MAC Address

PC-A จึงต้องค้นหาว่า

192.168.10.20
        |
        v
MAC Address = ?

ARP ช่วยให้ Host สามารถค้นหา MAC Address ที่สัมพันธ์กับ IPv4 Address ที่ต้องใช้บน Local Ethernet Network

ข้อควรจำ: ARP เป็นกลไกของ IPv4 ส่วน IPv6 ไม่ใช้ ARP แต่ใช้ Neighbor Discovery Protocol ซึ่งเป็นส่วนหนึ่งของ ICMPv6 สำหรับงานที่เกี่ยวข้องกับ Neighbor Discovery

ทำไมต้องมี ARP?

เมื่อ Application ต้องการส่งข้อมูล ไปยัง IPv4 Address ปลายทาง ระบบอาจทราบ Destination IP แล้ว แต่ Ethernet Interface ยังต้องสร้าง Ethernet Frame สำหรับส่งผ่าน Local Link

แนวคิด:

Layer 3

Destination IP
192.168.10.20

       |
       v

Layer 2

Destination MAC
AAAA.BBBB.CCCC

ดังนั้น Host ต้องมีวิธี Mapping ระหว่าง IPv4 Address กับ MAC Address ที่ต้องใช้ สำหรับ Next Hop บน Local Network

ARP Request และ ARP Reply ทำงานอย่างไร?

สมมติ:

PC-A
IP  192.168.10.10
MAC AAAA.AAAA.AAAA

PC-B
IP  192.168.10.20
MAC BBBB.BBBB.BBBB

ทั้งสองเครื่องอยู่ใน Subnet:

192.168.10.0/24

Step 1 — PC-A ตรวจสอบ ARP Cache

ก่อนส่ง ARP Request PC-A จะตรวจสอบว่ามี Mapping ของ 192.168.10.20 อยู่แล้วหรือไม่

Step 2 — ส่ง ARP Request

หากยังไม่มีข้อมูล PC-A ส่ง ARP Request บน Local Network

PC-A

Who has 192.168.10.20?

Tell 192.168.10.10

        |
        v

Ethernet Broadcast

FF:FF:FF:FF:FF:FF

ARP Request ในกรณีทั่วไป ถูกส่งเป็น Ethernet Broadcast ทำให้อุปกรณ์ภายใน Broadcast Domain สามารถรับ Request ได้

Step 3 — PC-B ตอบ ARP Reply

PC-B พบว่า Target IPv4 Address ตรงกับ Address ของตัวเอง จึงส่ง ARP Reply กลับ

PC-B

192.168.10.20 is at
BBBB.BBBB.BBBB

        |
        v

PC-A

Step 4 — PC-A บันทึก ARP Entry

192.168.10.20
       |
       v
BBBB.BBBB.BBBB

จากนั้น PC-A สามารถสร้าง Ethernet Frame ที่มี Destination MAC Address ของ PC-B และส่งข้อมูลต่อได้

ARP Table คืออะไร?

ARP Table หรือ ARP Cache เก็บ Mapping ระหว่าง IPv4 Address กับ MAC Address ที่ Host เรียนรู้หรือกำหนดไว้

บน Windows สามารถตรวจสอบด้วย:

arp -a

ตัวอย่าง:

Internet Address      Physical Address
192.168.10.1          00-11-22-33-44-55
192.168.10.20         aa-bb-cc-dd-ee-ff

Operating System สมัยใหม่อาจมีคำสั่ง หรือโครงสร้าง Neighbor Table เพิ่มเติม แต่ arp -a ยังเป็นคำสั่งพื้นฐานที่มีประโยชน์ สำหรับตรวจสอบ IPv4 ARP Cache บน Windows

ARP Table กับ MAC Address Table ต่างกันอย่างไร?

สองคำนี้มักถูกสับสน แต่ทำหน้าที่ต่างกัน

หัวข้อ ARP Table MAC Address Table
Mapping IPv4 Address → MAC Address MAC Address → Switch Port
พบใน Host / Router / Layer 3 Device Ethernet Switch
เกี่ยวข้องกับ ARP / Neighbor Resolution Layer 2 Switching
ใช้เพื่อ หา MAC ของ Local Neighbor หรือ Next Hop หา Port สำหรับ Forward Ethernet Frame

จำง่าย ๆ:

ARP Table

IP
 |
 v
MAC


MAC Address Table

MAC
 |
 v
Switch Port

ARP กับ Default Gateway

หาก Destination อยู่ต่าง Subnet Host ไม่ได้ ARP หา MAC Address ของ Remote Destination โดยตรง ในกรณี Routing ปกติ

Host จะส่ง Packet ไปยัง Next Hop เช่น Default Gateway จึงต้องรู้ MAC Address ของ Gateway บน Local Link

ตัวอย่าง:

PC-A
192.168.10.10/24

ต้องการไป

8.8.8.8

        |
        v

Destination อยู่นอก Local Subnet

        |
        v

Default Gateway
192.168.10.1

        |
        v

ARP:

Who has 192.168.10.1?

จากนั้น PC-A สามารถสร้าง Frame โดยใช้:

Destination IP
8.8.8.8

Destination MAC
MAC ของ Default Gateway
IP Destination ของ Packet ยังคงเป็น Remote Destination ส่วน Ethernet Destination MAC ใช้ Address ของ Next Hop บน Local Ethernet Segment

ภาค 2: ARP Spoofing และความเสี่ยง

ARP Spoofing / ARP Poisoning คืออะไร?

ARP ถูกออกแบบมาในยุคที่ Local Network ไม่ได้มี Security Controls แบบปัจจุบันจำนวนมาก และ ARP เองไม่มี Authentication สำหรับยืนยันว่า ARP Information มาจากเจ้าของ IPv4 Address ที่แท้จริง

ARP Spoofing หรือ ARP Poisoning คือการส่ง ARP Information ที่เป็นเท็จ เพื่อทำให้อุปกรณ์อื่น สร้างหรือเปลี่ยน IP-to-MAC Mapping ไปยัง MAC Address ที่ไม่ควรใช้

ตัวอย่างเชิงแนวคิด:

PC
192.168.10.100

Gateway
192.168.10.1
MAC = GGGG.GGGG.GGGG

Untrusted Device
MAC = XXXX.XXXX.XXXX

ข้อมูล ARP ปลอมอาจพยายามทำให้ PC เชื่อว่า:

192.168.10.1
      |
      v
XXXX.XXXX.XXXX

แทนที่จะเป็น Mapping ที่ถูกต้อง:

192.168.10.1
      |
      v
GGGG.GGGG.GGGG

ARP Spoofing มีผลอย่างไร?

หาก ARP Mapping ถูกเปลี่ยนไปยังอุปกรณ์ที่ไม่ควรได้รับ Traffic อาจก่อให้เกิดผลกระทบ เช่น:

  • Traffic ถูกส่งผิดปลายทางใน Local Network
  • การเชื่อมต่อถูกขัดจังหวะ
  • เกิด Denial of Service
  • Traffic บางส่วนอาจถูก Redirect ผ่านอุปกรณ์อื่น
  • เพิ่มความเสี่ยงต่อ Man-in-the-Middle ในบางสถานการณ์
HTTPS, TLS, VPN และ End-to-End Security ยังคงมีความสำคัญ เพราะ Layer 2 Security Feature ไม่ควรถูกมองว่าแทนที่ Application หรือ Transport Security

ภาค 3: Dynamic ARP Inspection

Dynamic ARP Inspection หรือ DAI คืออะไร?

Dynamic ARP Inspection — DAI เป็น Layer 2 Security Feature บน Cisco Switch ที่รองรับ ซึ่งใช้ตรวจสอบ ARP Messages ก่อนอนุญาตให้ Traffic ผ่าน บน VLAN ที่เปิดใช้ DAI

แนวคิด:

ARP Message
     |
     v
Cisco Switch
     |
     v
Dynamic ARP Inspection
     |
     +------ Valid ------> Forward
     |
     +------ Invalid ----> Drop

DAI สามารถใช้ข้อมูลจาก DHCP Snooping Binding Database เพื่อตรวจสอบความสัมพันธ์ ของ IP Address, MAC Address, VLAN และ Interface สำหรับ DHCP Client

DAI ทำงานร่วมกับ DHCP Snooping อย่างไร?

นี่คือจุดที่บทความ DHCP Snooping เชื่อมเข้ากับ DAI โดยตรง

สมมติ DHCP Snooping Binding มีข้อมูล:

MAC Address       IP Address       VLAN   Interface
----------------------------------------------------
AAAA.AAAA.AAAA    192.168.10.101   10     Gi1/0/5
BBBB.BBBB.BBBB    192.168.10.102   10     Gi1/0/6

เมื่อ ARP Message เข้ามาจาก Untrusted Interface DAI สามารถตรวจสอบข้อมูล กับ Binding ที่เชื่อถือได้

DHCP
 |
 v
DHCP Snooping
 |
 v
Binding Database
 |
 |  IP + MAC + VLAN + Interface
 |
 v
Dynamic ARP Inspection
 |
 v
Validate ARP

หากข้อมูล ARP ไม่สอดคล้องกับ Binding Switch สามารถ Drop ARP Message ตาม DAI Policy

DAI Trusted และ Untrusted Port

DAI ใช้แนวคิด Trust Boundary เช่นเดียวกับ DHCP Snooping แต่ต้องเข้าใจว่า DHCP Snooping Trust และ DAI Trust เป็นการตั้งค่าคนละ Feature

Untrusted Port

โดยทั่วไป User-facing Access Ports ควรอยู่ในฝั่งที่ DAI ตรวจสอบ ARP

PC
 |
Gi1/0/5
DAI Untrusted
 |
Switch

Trusted Port

Interface ที่ได้รับความเชื่อถือ สามารถกำหนดเป็น DAI Trusted ตาม Network Topology

Trusted Infrastructure
        |
        |
     Gi1/0/24
     DAI Trust
        |
      Switch
อย่า Trust Port โดยไม่จำเป็น เพราะ ARP Messages ที่เข้าทาง DAI Trusted Port จะไม่ได้รับการตรวจสอบแบบเดียวกับ Untrusted Port การกำหนด Trust จึงต้องอิง Security Boundary จริง ไม่ใช่เพียงเพราะ Port นั้นเป็น Uplink

ตั้งค่า Dynamic ARP Inspection บน Cisco Switch

สมมติ Network:

VLAN 10
USERS

DHCP Snooping
Enabled

Gi1/0/1 - 20
Client Ports

Gi1/0/24
Trusted Infrastructure Uplink

Step 1 — เปิด DHCP Snooping

Switch# configure terminal

Switch(config)# ip dhcp snooping
Switch(config)# ip dhcp snooping vlan 10

Step 2 — Trust DHCP Uplink

Switch(config)# interface gigabitEthernet 1/0/24
Switch(config-if)# ip dhcp snooping trust
Switch(config-if)# exit

Step 3 — เปิด DAI บน VLAN 10

Switch(config)# ip arp inspection vlan 10

คำสั่งนี้เปิด Dynamic ARP Inspection สำหรับ VLAN 10

Step 4 — กำหนด DAI Trusted Port ตาม Topology

Switch(config)# interface gigabitEthernet 1/0/24
Switch(config-if)# ip arp inspection trust
Switch(config-if)# exit

Port อื่นที่ไม่ได้กำหนด Trust จะเป็น DAI Untrusted ตามค่าเริ่มต้นบน Platform ที่รองรับ

Step 5 — ตรวจสอบ Configuration

Switch# show ip arp inspection

ตรวจสอบ DHCP Snooping Binding:

Switch# show ip dhcp snooping binding

DAI ARP Validation

Cisco Platform บางรุ่นรองรับ การเพิ่ม Validation สำหรับ ARP Packet Fields ด้วยคำสั่ง:

Switch(config)# ip arp inspection validate src-mac dst-mac ip

แนวคิดของแต่ละตัวเลือก:

Option ตรวจสอบ
src-mac ความสอดคล้องของ Source MAC ที่เกี่ยวข้องใน Ethernet/ARP
dst-mac ความสอดคล้องของ Destination MAC ที่เกี่ยวข้องใน Ethernet/ARP
ip ตรวจสอบ ARP IP Fields บางประเภทที่ไม่ถูกต้องหรือไม่เหมาะสมตาม Validation Rules
Syntax และความสามารถของ DAI อาจแตกต่างตาม Cisco Platform และ IOS/IOS XE Version ก่อนนำ Configuration ไปใช้จริง ควรตรวจสอบ Command Reference ของอุปกรณ์และ Software Release ที่ใช้งาน

Static IP กับ DAI ต้องระวังอะไร?

จุดสำคัญของ DAI คือ DHCP Snooping Binding Database เกิดจาก DHCP Transaction

แต่หากอุปกรณ์ใช้ Static IP อาจไม่มี Dynamic DHCP Snooping Binding ให้ DAI ใช้ตรวจสอบ

ตัวอย่าง:

Printer

IP
192.168.10.50

Static Configuration

        |
        v

ไม่มี DHCP Lease

        |
        v

ไม่มี Dynamic DHCP Snooping Binding
จาก DHCP Transaction

ใน Network ที่มี Static Hosts อาจต้องออกแบบ ARP ACL หรือกลไกอื่นที่ Platform รองรับ เพื่อให้ DAI สามารถรองรับ Static Binding ได้อย่างเหมาะสม

ตัวอย่างเชิงแนวคิด:

Switch(config)# arp access-list STATIC-ARP
Switch(config-arp-nacl)# permit ip host 192.168.10.50 mac host aaaa.bbbb.cccc
Switch(config-arp-nacl)# exit

Switch(config)# ip arp inspection filter STATIC-ARP vlan 10
ตัวอย่างนี้มีไว้เพื่ออธิบายแนวคิด ไม่ควรคัดลอกไปใช้กับ Production โดยตรง ต้องตรวจสอบ Syntax, Platform, Static Hosts และ DAI Design ของ Network จริงก่อน

ARP Rate Limiting

DAI สามารถจำกัดอัตรา ARP Traffic บน Untrusted Interface เพื่อช่วยป้องกัน ARP Traffic ที่ผิดปกติหรือมากเกินกำหนด ตามความสามารถของ Platform

ตัวอย่าง:

Switch(config)# interface gigabitEthernet 1/0/5
Switch(config-if)# ip arp inspection limit rate 15
Switch(config-if)# exit

ค่า Rate Limit ต้องออกแบบให้เหมาะกับ Environment ไม่ควรใช้ค่าตัวอย่าง โดยไม่ประเมิน Traffic จริง

หากกำหนด ARP Rate Limit ต่ำเกินไป อาจทำให้ Port ถูกจัดการตาม Error/Violation Behavior ของ Platform และกระทบผู้ใช้งานจริงได้

ภาค 4: Troubleshooting DAI

Troubleshooting Dynamic ARP Inspection

1. ตรวจสอบ DHCP Snooping ก่อน

Switch# show ip dhcp snooping

ตรวจสอบว่า DHCP Snooping เปิดบน VLAN ที่ต้องการหรือไม่

2. ตรวจสอบ DHCP Snooping Binding

Switch# show ip dhcp snooping binding

หาก Client ใช้ DHCP แต่ไม่มี Binding DAI อาจไม่มีข้อมูลที่ต้องการ สำหรับ Validation ของ Dynamic Client

3. ตรวจสอบ DAI

Switch# show ip arp inspection

ตรวจสอบ:

  • DAI เปิดบน VLAN ถูกต้องหรือไม่
  • Interface ใด Trusted
  • Validation Configuration
  • ARP Rate Limit

4. ตรวจสอบ ARP Table บน Client

Windows:

arp -a

ตรวจสอบ MAC Address ของ Default Gateway และ Local Hosts ที่เกี่ยวข้อง

5. ตรวจสอบ MAC Address Table

Switch# show mac address-table

ใช้ตรวจสอบว่า Switch เรียนรู้ MAC Address จาก Interface ใด

6. ตรวจสอบ VLAN

Switch# show vlan brief

7. ตรวจสอบ Trunk

Switch# show interfaces trunk

8. ตรวจสอบ Log

Switch# show logging

Log สามารถช่วยระบุ DAI Drop หรือ Interface Event ตาม Platform และ Logging Configuration

Cisco Lab: DHCP Snooping + Dynamic ARP Inspection

Lab นี้สามารถใช้ทำความเข้าใจ ความสัมพันธ์ระหว่าง DHCP Snooping และ DAI บน Simulator หรือ Cisco Lab Environment ที่รองรับ Feature ดังกล่าว

Topology

                 DHCP Server
                     |
                     |
                Trusted Path
                     |
              +--------------+
              | Cisco Switch |
              +--------------+
                /          \
               /            \
          Gi1/0/5          Gi1/0/6
             |                |
           PC-A             PC-B

         VLAN 10 USERS

Step 1 — VLAN

Switch(config)# vlan 10
Switch(config-vlan)# name USERS
Switch(config-vlan)# exit

Step 2 — Client Ports

Switch(config)# interface range gigabitEthernet 1/0/5 - 6
Switch(config-if-range)# switchport mode access
Switch(config-if-range)# switchport access vlan 10
Switch(config-if-range)# spanning-tree portfast
Switch(config-if-range)# exit

Step 3 — DHCP Snooping

Switch(config)# ip dhcp snooping
Switch(config)# ip dhcp snooping vlan 10

Step 4 — DHCP Trusted Path

สมมติ Gi1/0/24 เป็นเส้นทางที่ DHCP Server Responses เข้าสู่ Switch:

Switch(config)# interface gigabitEthernet 1/0/24
Switch(config-if)# ip dhcp snooping trust
Switch(config-if)# exit

Step 5 — ตรวจสอบ DHCP Binding

Switch# show ip dhcp snooping binding

ก่อนเปิด DAI ควรยืนยันว่า DHCP Clients มี Binding ที่ถูกต้อง

Step 6 — เปิด DAI

Switch(config)# ip arp inspection vlan 10

Step 7 — Trust Infrastructure Port หาก Design ต้องการ

Switch(config)# interface gigabitEthernet 1/0/24
Switch(config-if)# ip arp inspection trust
Switch(config-if)# exit

Step 8 — Verify

Switch# show ip arp inspection
Switch# show ip dhcp snooping binding
Switch# show mac address-table

Step 9 — ตรวจสอบ Client

Windows:

ipconfig /all
arp -a
ping 192.168.10.1

ควรตรวจสอบว่า Client ยังสามารถเข้าถึง Default Gateway และ Network Services ได้ตามปกติหลังเปิด DAI

คำสั่ง Cisco ที่ควรรู้

Command หน้าที่
ip dhcp snooping เปิด DHCP Snooping
ip dhcp snooping vlan 10 เปิด DHCP Snooping สำหรับ VLAN 10
ip dhcp snooping trust กำหนด DHCP Snooping Trusted Interface
show ip dhcp snooping binding ตรวจสอบ DHCP Snooping Binding Database
ip arp inspection vlan 10 เปิด DAI บน VLAN 10
ip arp inspection trust กำหนด DAI Trusted Interface
ip arp inspection validate ... เพิ่ม ARP Validation ตาม Platform
ip arp inspection limit rate ... กำหนด ARP Rate Limit
show ip arp inspection ตรวจสอบ DAI Configuration และ Status
show mac address-table ตรวจสอบ MAC Address Table
show vlan brief ตรวจสอบ VLAN
show interfaces trunk ตรวจสอบ Trunk
show logging ตรวจสอบ System Log

ภาค 5: Layer 2 Security Architecture

DHCP Snooping + DAI + IP Source Guard ทำงานร่วมกันอย่างไร?

เมื่อมองภาพรวม Security Features ทั้งสาม สามารถต่อยอดกันเป็นลำดับ

                 DHCP Client
                      |
                      v
              +----------------+
              | DHCP Snooping  |
              +----------------+
                      |
                      v
        DHCP Snooping Binding Database
                      |
           +----------+----------+
           |                     |
           v                     v
+----------------------+  +------------------+
| Dynamic ARP          |  | IP Source Guard  |
| Inspection           |  |                  |
+----------------------+  +------------------+
           |                     |
           v                     v
     Validate ARP          Validate Source
       Traffic              IP / Binding

แต่ละ Feature มีหน้าที่แตกต่างกัน:

Feature หน้าที่หลัก
DHCP Snooping ควบคุม DHCP Server Messages และสร้าง Binding Database
Dynamic ARP Inspection ตรวจสอบ ARP Messages เพื่อลดความเสี่ยงจาก ARP Spoofing
IP Source Guard ตรวจสอบ Source IP Traffic บน Access Port ตาม Binding/Policy

จึงสามารถมอง Security Chain ได้ว่า:

Rogue DHCP
     |
     v
DHCP Snooping


ARP Spoofing
     |
     v
Dynamic ARP Inspection


IP Spoofing
     |
     v
IP Source Guard

อย่างไรก็ตาม Feature เหล่านี้ ไม่ได้แทนที่ Firewall, 802.1X, Endpoint Security, Network Segmentation หรือ Monitoring แต่เป็นองค์ประกอบของ Defense-in-Depth Architecture

คำถามที่พบบ่อย — FAQ

ARP ย่อมาจากอะไร?

ARP ย่อมาจาก Address Resolution Protocol ใช้ค้นหาความสัมพันธ์ระหว่าง IPv4 Address และ Layer 2 Address เช่น Ethernet MAC Address บน Local Network

ARP ใช้กับ IPv6 หรือไม่?

ไม่ใช้ IPv6 ใช้ Neighbor Discovery ผ่าน ICMPv6 แทน ARP

ARP Request เป็น Broadcast หรือไม่?

ใน Ethernet LAN ทั่วไป ARP Request สำหรับค้นหา Local Neighbor ถูกส่งเป็น Ethernet Broadcast ไปยัง FF:FF:FF:FF:FF:FF

ARP Reply เป็น Broadcast หรือไม่?

ARP Reply สำหรับ Request ปกติ โดยทั่วไปสามารถตอบกลับเป็น Unicast ไปยังผู้ร้องขอ แต่ ARP มีรูปแบบและกรณีใช้งานอื่นเพิ่มเติม เช่น Gratuitous ARP

ARP Table กับ MAC Address Table เหมือนกันหรือไม่?

ไม่เหมือนกัน ARP Table ใช้ Mapping IPv4 → MAC ขณะที่ Switch MAC Address Table ใช้ Mapping MAC → Interface

ARP Spoofing คืออะไร?

คือการส่ง ARP Information ที่เป็นเท็จ เพื่อทำให้อุปกรณ์อื่น เรียนรู้ IP-to-MAC Mapping ที่ไม่ควรใช้

Dynamic ARP Inspection ป้องกันอะไร?

DAI ช่วยตรวจสอบ ARP Messages และลดความเสี่ยงจาก ARP Spoofing โดยสามารถใช้ข้อมูล จาก DHCP Snooping Binding Database เป็นแหล่งตรวจสอบสำหรับ Dynamic DHCP Clients

DAI ต้องใช้ DHCP Snooping หรือไม่?

DAI สามารถใช้ DHCP Snooping Binding Database เป็นแหล่งข้อมูลหลักสำหรับ Dynamic DHCP Clients ส่วน Static Hosts อาจต้องใช้ ARP ACL หรือ Configuration เพิ่มเติม ตาม Network Design และ Platform

DHCP Snooping Trust กับ DAI Trust เหมือนกันหรือไม่?

ไม่ใช่ Configuration เดียวกัน

ip dhcp snooping trust

ใช้กับ DHCP Snooping ส่วน:

ip arp inspection trust

ใช้กับ Dynamic ARP Inspection

เปิด DAI แล้ว Static IP ใช้งานไม่ได้ เกิดจากอะไร?

หนึ่งในสาเหตุที่ควรตรวจสอบคือ Static Host ไม่มี Dynamic DHCP Snooping Binding จึงต้องตรวจสอบ ARP ACL, Static Binding หรือ DAI Design ที่ Platform รองรับ

DAI ใช้แทน Firewall ได้หรือไม่?

ไม่ได้ DAI เป็น Layer 2 Security Control ที่เน้น ARP Validation ไม่ได้ทำหน้าที่แทน Firewall หรือ Access Control ใน Layer อื่น

สรุป

ARP — Address Resolution Protocol เป็นกลไกสำคัญของ IPv4 Network ที่ช่วยค้นหาความสัมพันธ์ระหว่าง IPv4 Address กับ MAC Address ที่ต้องใช้บน Local Link

เมื่อ Host ต้องการสื่อสารกับเครื่องใน Local Subnet มันสามารถใช้ ARP เพื่อค้นหา MAC Address ของ Destination แต่หาก Destination อยู่ต่าง Subnet Host โดยทั่วไปจะ ARP หา MAC Address ของ Next Hop เช่น Default Gateway แทน

เนื่องจาก ARP ไม่มี Authentication สำหรับยืนยันเจ้าของ Mapping โดยตรง จึงมีความเสี่ยงจาก ARP Spoofing / ARP Poisoning ซึ่งอาจทำให้ Traffic ถูก Redirect หรือเกิด Network Disruption

บน Cisco Switch ที่รองรับ Dynamic ARP Inspection — DAI สามารถตรวจสอบ ARP Messages โดยอาศัย DHCP Snooping Binding Database และ Security Policy ที่กำหนด เพื่อลดความเสี่ยงจาก ARP Spoofing

จุดสำคัญคือ DHCP Snooping → DAI → IP Source Guard เป็นชุดแนวคิดที่เชื่อมต่อกัน โดย DHCP Snooping ช่วยสร้าง Binding Information, DAI ใช้ข้อมูลดังกล่าวช่วยตรวจสอบ ARP และ IP Source Guard สามารถนำ Binding ไปช่วยตรวจสอบ Source IP Traffic ที่ Access Port

ดังนั้นเมื่อเข้าใจ DAI แล้ว หัวข้อถัดไปที่เหมาะสมคือ IP Source Guard บน Cisco Switch: ป้องกัน IP Spoofing ด้วย DHCP Snooping Binding

Share this
Facebook Share X
TECHEREST COMMUNITY

Share your thoughts here

Join the conversation and share your perspective on this article.

Comments will load when you reach this section.