We have DHCP snooping and ARP inspection enabled on our 3750G switches for our Voice and Data VLANs. It works great--unless the switch is reloaded, like during a SW upgrade.
When the switch reloads, none of the phones are able to get IPs from DHCP. The data VLANs don't seem to be affected. The log buffers on the switches show DHCP SPOOFING DENY (Invalid ARPs) errors. Only after I disable ARP inspection for the voice VLANs do the phones come up.
OK, so am I doing something wrong? Shouldn't I be able to have ARP inspection enabled for the voice VLAN as well? Perhaps I'm doing something out of order, like I should disable ARP inspection, reload, then re-enable it after all phones get IPs and come up? If Inspection really works, I shouldn't have to do that.
The latest incident occurred after I simply reloaded the switch in the middle of the night after downloading and installing the new SW image (12.2.52SE-ipbase). In the morning when I got in, all the phones were "Configuring IP."
Any suggestions or common experiences that anyone can offer? Thank in advance.
Thank you for the reply. I have configured the DHCP snooping database to be stored in flash for now until I can set up an external TFTP server. Until then, I am noticing something else.
In order to allow the phones to receive an IP address from DHCP, I had to disable ARP inspection and DHCP Snooping on the voice VLANs. I then re-enabled just DHCP Snooping. I reset several test phones, and all were able to reset and get an IP address successfully. However, I am not seeing any entries for the phones in the 'sh ip dhcp snooping binding' output. Is this because I am now using a snooping database? Previously, all phones and hosts on both the data and voice VLANs showed in the output of that command. I just want to make sure that it is all working before I re-enable 'ip arp inspection' on the voice VLANs.
We are pleased to announce availability of Beta software for 16.6.3. 16.6.3 will be the second rebuild on the 16.6 release train targeted towards Catalyst 9500/9400/9300/3850/3650 switching platforms. We are looking for early feedback from custome...