cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
432
Views
10
Helpful
4
Replies

ip dhcp snooping

carl_townshend
Spotlight
Spotlight

can anyone tell me what ip dhcp snooping

means ?

4 Replies 4

It means a few things - basically

1) In configuration terms, you enable it globally on the switch, then on each VLAN you want, then set each port on the switch to either 'untrusted' or 'trusted' - with trusted being a port where you would expect DHCP offers to be rec'd (i.e. server ports or uplinks), and untrusted being a port where you would expect DHCP Discover packets (i.e. end user ports).

2) It prevents DHCP offers coming from 'edge' or 'untrusted' ports - for example stopping someone plugging in an AP or web router that gives out DHCP and disrupts service on your net work.

3) It also does several other checks - e.g. checks that DHCP packets on 'untrusted' ports are being sent for only real MAC addresses on the port (so one PC can't use up all your scope addresses, or release someone else's IP address lease).

Regards

Aaron

Please rate helpful posts...

Aaron Please remember to rate helpful posts to identify useful responses, and mark 'Answered' if appropriate!

so is this a global or per port command ?

This is helpful.

Do you have any experience with configuring trunks for this?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card