From the course: Cisco Certified Network Associate (CCNA) v1.1 (200-301) Cert Prep

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

Dynamic ARP Inspection (DAI) theory

Dynamic ARP Inspection (DAI) theory

- [Instructor] In our previous video, we considered DHCP snooping. And if an attacker were able to send DHCP IP address information to an unsuspecting victim, that attacker might convince the victim's MAChine that the attacker is the default gateway that that victim's computer should use, and that could allow the attacker to intercept messages being sent by that victim MAChine. This is a type of man in the middle attacker. Sometimes that's called an on path attack, but it's when an attacker is intercepting or getting a copy of packets being sent to or from the victim MAChine and while DHCP snooping is one way to do that, in this video, we want to consider another way and talk about a prevention mechanism. Another way that an attacker might inject themselves into the path of legitimate data flow and maybe capture that traffic is to do an ARP poisoning attack. Let's review how PC1 would typically get out to the internet when it first booted up. We'll say that PC1 learned via DHCP, that…

Contents