Re: DHCP Snooping and DAI

From: sabrina pittarel (sabri_esame@yahoo.com)
Date: Sun Dec 17 2006 - 03:19:56 ART


Hi Nick,
does it help to think that regardless of DHCP snooping or DAI, for a
host to reply to an ARP request it needs to have an IP address already
assigned?

DHCP Snooping and DAI do not make any change to the above
consideration.

As soon as the client is ready to reply to ARP request i.e. it
got its ip address, DHCP snooping database is also ready with the proper host
entry.
The DHCP Snooping database is updated when the DHCP Ack message is
received from the server...that is the same message used by the client to
assign the ip address to itself.

Essentially, the host becomes ready to reply
to ARP requests at the same time that DAI on the switch is ready to accept its
arp replies

Sabrina

----- Original Message ----
From: Nick Griffin
<nick.jon.griffin@gmail.com>
To: groupstudy <ccielab@groupstudy.com>
Sent:
Saturday, December 16, 2006 5:41:19 PM
Subject: DHCP Snooping and DAI

I
understand the concept of both these, however I have a few questions I'm
hoping someone using in production or a lab environment can clarify. In
order
to use DAI, I must have a valid mapping in my dhcp snooping database,
this is
fine assuming you enable dhcp snooping prior to DAI and build as
well as store
the dhcp binding database on a tftp server somewhere. So, what
happens when
new clients come online on a vlan with DAI and DHCP Snooping
configured? Will
the client be able to obtain an ip address to create the
DHCP database entry
for DAI to validate against? I'm probably missing
something here, but my
trials lead me to believe the database must contains
the host entries first,
or manual entries for DAI for the client must be
statically entered. Thoughts
are appreciated.

Nick Griffin



This archive was generated by hypermail 2.1.4 : Tue Jan 02 2007 - 07:50:38 ART