Description

For Juniper Networks EX Series Switches, after deploying Dynamic ARP Inspection and IP Source Guard using Mist templates or regular CLI configuration, you might face issues with connectivity if there are live clients, persistent MAC learning, or static IP addresses in use.

Symptoms

For devices with persistent MAC learning enabled, the following log might be seen:

AS_PKT_DAI_FAILED: DAI FAILED: ARP REQUEST received, interface ge-2/0/20.0 [index 679], vlan-id 30, sender ip/mac 10.10.10.1/aa:bb:cc:dd:ee:ff, receiver ip/mac 10.10.10.10/00:00:00:00:00:00 

And failures under "show dhcp-security arp inspection statistics" and missing entries on "show dhcp-security binding".

Solution

To deploy this it is recommended to do the following:

  • Disable persistent mac learning (sticky mac) from the port profile under the template or switch and any other port profile where this will be applied. If you are not using Mist, make sure there is no persistent mac learning configured.
  • Make sure there are no static IP addresses in the VLANs where this is enabled.
  • Clear all MAC addresses from the MAC table.
  • Make sure no clients have an assigned DHCP address.
  • Do not enable this for wireless vlans, as if the client roams from an AP connected to one switch to a second AP on a different switch this will affect the user and they will have to clear the MAC and clear the DHCP entry. For wireless deployments you should use dot1x.

​For any issues, review the statistics and DAI failures in the log messages. 

Modification History

2024-02-01 : Article Created

2025-09-16: Published as external.

Related Information

https://www.juniper.net/documentation/us/en/software/junos/security-services/topics/topic-map/understanding_and_using_persistent_mac_learning.html

https://www.juniper.net/documentation/en_US/junos/topics/concept/layer-2-8021x-port-network-authentication-security-understanding.html

https://www.mist.com/documentation/dhcp-snooping-and-port-security-considerations/