<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DHCP Snooping in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dhcp-snooping/m-p/4977541#M1106895</link>
    <description>&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;I have configured DHCP snooping on cisco switch and configured two DHCP scope on R1 and R2 to test the DHCP snooping functionality.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Config output from the switch&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;#ip dhcp snooping&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;#ip dhcp snooping vlan 1&lt;/LI&gt;&lt;LI&gt;#interface range fast 0/2-3&lt;/LI&gt;&lt;LI&gt;#ip dhcp snooping trust&lt;/LI&gt;&lt;LI&gt;#exit&lt;/LI&gt;&lt;LI&gt;#inet fast 0/1&lt;/LI&gt;&lt;LI&gt;#ip dhcp snooping limit rate 100&lt;/LI&gt;&lt;LI&gt;#exit&lt;/LI&gt;&lt;LI&gt;wr.....&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Although both f0/2 and 0/3 ports are put into trusted status,&amp;nbsp; the end point which is on port 0/1 takes APIPA ip address, what is wrong with DHCP snooping or i forgot some commands ????&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NawidKarimi_0-1702505916299.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/204949i19AADA820ADE513D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="NawidKarimi_0-1702505916299.png" alt="NawidKarimi_0-1702505916299.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Wed, 13 Dec 2023 22:24:02 GMT</pubDate>
    <dc:creator>Abdul salaam</dc:creator>
    <dc:date>2023-12-13T22:24:02Z</dc:date>
    <item>
      <title>DHCP Snooping</title>
      <link>https://community.cisco.com/t5/network-security/dhcp-snooping/m-p/4977541#M1106895</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;I have configured DHCP snooping on cisco switch and configured two DHCP scope on R1 and R2 to test the DHCP snooping functionality.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Config output from the switch&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;#ip dhcp snooping&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;#ip dhcp snooping vlan 1&lt;/LI&gt;&lt;LI&gt;#interface range fast 0/2-3&lt;/LI&gt;&lt;LI&gt;#ip dhcp snooping trust&lt;/LI&gt;&lt;LI&gt;#exit&lt;/LI&gt;&lt;LI&gt;#inet fast 0/1&lt;/LI&gt;&lt;LI&gt;#ip dhcp snooping limit rate 100&lt;/LI&gt;&lt;LI&gt;#exit&lt;/LI&gt;&lt;LI&gt;wr.....&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Although both f0/2 and 0/3 ports are put into trusted status,&amp;nbsp; the end point which is on port 0/1 takes APIPA ip address, what is wrong with DHCP snooping or i forgot some commands ????&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NawidKarimi_0-1702505916299.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/204949i19AADA820ADE513D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="NawidKarimi_0-1702505916299.png" alt="NawidKarimi_0-1702505916299.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 13 Dec 2023 22:24:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dhcp-snooping/m-p/4977541#M1106895</guid>
      <dc:creator>Abdul salaam</dc:creator>
      <dc:date>2023-12-13T22:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Snooping</title>
      <link>https://community.cisco.com/t5/network-security/dhcp-snooping/m-p/4977545#M1106896</link>
      <description>&lt;P&gt;May be i am reading wrong here, as per diagram you are trusted both ports (of DHCP here)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or config mistake, you should trust only the DHCP Server trust the legitimate one.&lt;/P&gt;
&lt;P&gt;Also check on the DHCP Server (router configured as expected)&lt;/P&gt;
&lt;P&gt;make sure all working and need to test DHCP snooping, shutdown Fas 0/3 port and check DHCP working before and then implement snooping trust.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 22:38:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dhcp-snooping/m-p/4977545#M1106896</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-12-13T22:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Snooping</title>
      <link>https://community.cisco.com/t5/network-security/dhcp-snooping/m-p/4977548#M1106897</link>
      <description>&lt;P&gt;I intentionally put both dhcp ports into trust status if any of them work but none work since dhcp snooping enabled on switch.&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is nothing wrong with the dhcp servers. i tested them before dhcp snooping !!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 22:42:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dhcp-snooping/m-p/4977548#M1106897</guid>
      <dc:creator>Abdul salaam</dc:creator>
      <dc:date>2023-12-13T22:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Snooping</title>
      <link>https://community.cisco.com/t5/network-security/dhcp-snooping/m-p/4977603#M1106898</link>
      <description>&lt;P&gt;in that case try adding below command to switch global config and test it :&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="uiOutputText"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="uiOutputText"&gt;no ip dhcp snooping information option&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Since both DHCP Server port are trusted, who ever first reply the client get that DHCP Server IP address.&lt;/P&gt;
&lt;P&gt;#show ip dhcp snooping statistics&amp;nbsp; (this command help you on switch see the Packets are forwarding or not)&lt;/P&gt;
&lt;P&gt;example :&lt;/P&gt;
&lt;P&gt;SW#show ip dhcp snooping statistics&lt;BR /&gt;Packets Forwarded = 8&lt;BR /&gt;Packets Dropped = 0&lt;BR /&gt;Packets Dropped From untrusted ports = 0&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2023 23:05:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dhcp-snooping/m-p/4977603#M1106898</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-12-13T23:05:56Z</dc:date>
    </item>
  </channel>
</rss>

