IP Device Tracking on routers
IP Device Tracking (IPDT) is a feature used in Cisco routers and switches to monitor IPv4 devices connected on LAN ports by associating their MAC and IP addresses.
Key functionalities:
-
Sends unicast Address Resolution Protocol (ARP) probes at a default interval of 30 seconds to maintain the tracking table
-
Supports integration with security features like IP ARP Inspection and DHCP Snooping.Extracts device identity (MAC and IP address) from network traffic.
-
Tracks the presence, location, and movement of end-nodes in the network.
-
Stores this information in a binding table for use by other security features.
Feature name |
Release information |
Feature description |
---|---|---|
IP Device Tracking on routers |
Release 17.18.1a |
Enables IP Device Tracking with SISF support on LAN ports for IPv4 device monitoring and enhanced security integration. |
Switch Integrated Security Features (SISF) based device tracking
The Switch Integrated Security Features (SISF)-based device tracking feature actively monitors the presence, location, and movement of end-nodes within the network as part of the First-Hop Security (FHS) suite. The feature enables the router to snoop incoming traffic, extract device identities (MAC and IP addresses), and store them in a binding table. Many features, including IEEE 802.1X, web authentication, Cisco TrustSec, and LISP, rely on the accuracy of this information to function correctly.
For more information on SISF, see the Chapter: Configuring Switch Integrated Security Features in the Security Configuration Guide