cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
320
Views
7
Helpful
4
Replies

dchp snooping

carl_townshend
Spotlight
Spotlight

Hi all, after a rogue adsl router nearly bought my clients to a halt over the weekend. I am going to look into implenting dhcp snooping.

Firstly, Can anyone tell me where we do this, do we do it on all switches, or do layer 3 switches only support this ? also how does it work in a simple way, i believe you simply set the port for dhcp to trusted and the others to non trusted, is this right ?, and can it cause any issues ?

cheers

Carl

4 Replies 4

John Blakley
VIP Alumni
VIP Alumni

Carl,

You would add dhcp snooping on all of the switches that interconnect. When you enable dhcp snooping globally, I believe (others can correct me) ALL ports are untrusted, and you have to enable the trusted port (the port that you KNOW a valid DHCP server is on) manually. You can run DHCP snooping on 2950 (L2) switches, but I can't speak for, say the Cisco Express 500 series.

Here's a link for more reading:

http://www.cisco.com/en/US/docs/switches/lan/catalyst2950/software/release/12.1_19_ea1/configuration/guide/swdhcp82.html

HTH,

John

HTH, John *** Please rate all useful posts ***

I have been reading some docs, it says I should have my uplink ports to other swithes as trusted, does this sound about right ?

Yes. If you have switches connected to multiple switches, then the connected trunk ports should be trusted. If you have an untrusted trunk port and it sees a dhcp packet come across it, it will shut the port down in an err-disabled state (I believe).

HTH,

John

HTH, John *** Please rate all useful posts ***

griffijo
Level 1
Level 1

I just wanted to add one comment, because it is a mistake I have made in the past. If you have Etherchannel trunks between your switches, you have to trust both your phycical ports that belong to the channel-group and the logical interface, i.e. "interface Port-channel1".

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card