cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
514
Views
0
Helpful
2
Replies

Why and when to use ip arp inspect trust/ip dhcp snoop trust

Steve Coady
Level 1
Level 1

All

Thankyou in advance.

sMc
1 Accepted Solution

Accepted Solutions

John Blakley
VIP Alumni
VIP Alumni

DHCP snooping trust is used on ports that you expect a dhcpoffer packet should come from. You generally trust the port that your server is on, and you trust the interswitch uplinks so the offer doesn't get dropped.

Arp inspection trust is used when you don't want to perform arp inspection on a packet. The arp inspection is done against the dhcp snooping database and allows packets that have a valid ip-mac binding in the database. If there is not a valid entry, then the packet is dropped. Cisco recommends that you configure all switchports to hosts as untrusted, but configure all links to other switches as trusted.

HTH,
John

*** Please rate all useful posts ***

HTH, John *** Please rate all useful posts ***

View solution in original post

2 Replies 2

John Blakley
VIP Alumni
VIP Alumni

DHCP snooping trust is used on ports that you expect a dhcpoffer packet should come from. You generally trust the port that your server is on, and you trust the interswitch uplinks so the offer doesn't get dropped.

Arp inspection trust is used when you don't want to perform arp inspection on a packet. The arp inspection is done against the dhcp snooping database and allows packets that have a valid ip-mac binding in the database. If there is not a valid entry, then the packet is dropped. Cisco recommends that you configure all switchports to hosts as untrusted, but configure all links to other switches as trusted.

HTH,
John

*** Please rate all useful posts ***

HTH, John *** Please rate all useful posts ***

Thank you

sMc
Review Cisco Networking products for a $25 gift card