<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC DHCP Proxy mode and DHCP Snooping on upstream switch in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-dhcp-proxy-mode-and-dhcp-snooping-on-upstream-switch/m-p/4928834#M260964</link>
    <description>&lt;P&gt;you are right you have to have ip dhcp snooping information option allow-untrusted.&lt;/P&gt;
&lt;P&gt;by default its disabled.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Sep 2023 14:18:46 GMT</pubDate>
    <dc:creator>Ambuj M</dc:creator>
    <dc:date>2023-09-25T14:18:46Z</dc:date>
    <item>
      <title>WLC DHCP Proxy mode and DHCP Snooping on upstream switch</title>
      <link>https://community.cisco.com/t5/wireless/wlc-dhcp-proxy-mode-and-dhcp-snooping-on-upstream-switch/m-p/4928751#M260961</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;is there an issue when we have WLC DHCP proxy mode and upstream switch with DHCP snooping enabled?&lt;/P&gt;
&lt;P&gt;Based on docs, WLC in proxy mode changes giaddr field (and can insert option-82 as well) and switch ignores DHCP messages over untrusted ports if it has non-zero giaddr field or option-82 (like relay info inserted).&lt;/P&gt;
&lt;P&gt;Then, it should be problematic for DHCP snooping enabled environment, right? We need to make trust WLC connected ports (which disables snooping checks for those ports, in reality) or configure L2 ports as ip dhcp relay trusted. Did anyone had&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 12:20:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-dhcp-proxy-mode-and-dhcp-snooping-on-upstream-switch/m-p/4928751#M260961</guid>
      <dc:creator>Kanan Huseynli</dc:creator>
      <dc:date>2023-09-25T12:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: WLC DHCP Proxy mode and DHCP Snooping on upstream switch</title>
      <link>https://community.cisco.com/t5/wireless/wlc-dhcp-proxy-mode-and-dhcp-snooping-on-upstream-switch/m-p/4928772#M260962</link>
      <description>&lt;P&gt;snooping dictates where offer comes from not where discover comes from, so dont think this should be an issue&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 12:54:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-dhcp-proxy-mode-and-dhcp-snooping-on-upstream-switch/m-p/4928772#M260962</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2023-09-25T12:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: WLC DHCP Proxy mode and DHCP Snooping on upstream switch</title>
      <link>https://community.cisco.com/t5/wireless/wlc-dhcp-proxy-mode-and-dhcp-snooping-on-upstream-switch/m-p/4928809#M260963</link>
      <description>&lt;P&gt;No, snooping has some checks for client messages as well.&lt;/P&gt;
&lt;P&gt;For example, when you have access and distro switch with both snooping enabled where access inserts option82, then distro switch ignores client messages. We normally either remove option82 on access OR allow it on untrusted port on distro switch.&lt;/P&gt;
&lt;P&gt;I assume then same happens in WLC, but can not get confirmation since I dont have WLC Lab&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 13:50:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-dhcp-proxy-mode-and-dhcp-snooping-on-upstream-switch/m-p/4928809#M260963</guid>
      <dc:creator>Kanan Huseynli</dc:creator>
      <dc:date>2023-09-25T13:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: WLC DHCP Proxy mode and DHCP Snooping on upstream switch</title>
      <link>https://community.cisco.com/t5/wireless/wlc-dhcp-proxy-mode-and-dhcp-snooping-on-upstream-switch/m-p/4928834#M260964</link>
      <description>&lt;P&gt;you are right you have to have ip dhcp snooping information option allow-untrusted.&lt;/P&gt;
&lt;P&gt;by default its disabled.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 14:18:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-dhcp-proxy-mode-and-dhcp-snooping-on-upstream-switch/m-p/4928834#M260964</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2023-09-25T14:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: WLC DHCP Proxy mode and DHCP Snooping on upstream switch</title>
      <link>https://community.cisco.com/t5/wireless/wlc-dhcp-proxy-mode-and-dhcp-snooping-on-upstream-switch/m-p/4932171#M261170</link>
      <description>&lt;P&gt;DHCP proxy only applies to the old AireOS based WLCs which are almost end of life.&amp;nbsp; If you are designing for future then you should be looking at the 9800 series WLCs.&lt;/P&gt;
&lt;P&gt;If you use 9800 series WLC as per the Best Practice guide (link below) then you should not configure SVI on the 9800 at all and leave the snooping/forwarding/relaying to the attached infrastructure.&amp;nbsp; If you do configure SVI with helper address/dhcp relay then it will be doing standards based DHCP relay not DHCP proxy.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Oct 2023 22:58:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-dhcp-proxy-mode-and-dhcp-snooping-on-upstream-switch/m-p/4932171#M261170</guid>
      <dc:creator>Rich R</dc:creator>
      <dc:date>2023-10-01T22:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: WLC DHCP Proxy mode and DHCP Snooping on upstream switch</title>
      <link>https://community.cisco.com/t5/wireless/wlc-dhcp-proxy-mode-and-dhcp-snooping-on-upstream-switch/m-p/4932911#M261225</link>
      <description>&lt;P&gt;Thank you, but since it is DHCP relay then giaddr will be modified and infrastructure dhcp snooping enabled switch will ignore these messages over untrusted.&lt;/P&gt;
&lt;P&gt;Seems, if it is not bridge mode then ip dhcp snooping trust is needed&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 18:42:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-dhcp-proxy-mode-and-dhcp-snooping-on-upstream-switch/m-p/4932911#M261225</guid>
      <dc:creator>Kanan Huseynli</dc:creator>
      <dc:date>2023-10-02T18:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: WLC DHCP Proxy mode and DHCP Snooping on upstream switch</title>
      <link>https://community.cisco.com/t5/wireless/wlc-dhcp-proxy-mode-and-dhcp-snooping-on-upstream-switch/m-p/4932916#M261227</link>
      <description>&lt;P&gt;Ip dhcp snooping trust toward wlc is not needed since the wlc is represent client here.&lt;/P&gt;
&lt;P&gt;The modify of dhcp and add op82 is need I think.&lt;/P&gt;
&lt;P&gt;Now&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Wlc add op82 send to SW (with dhcp snooping) what you need is&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Ip dhcp snooping information option &lt;STRONG&gt;allow-untrusted&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Why untrust ? Since the port is untrust and wlc add op82 then this need.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Oct 2023 19:01:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-dhcp-proxy-mode-and-dhcp-snooping-on-upstream-switch/m-p/4932916#M261227</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-10-02T19:01:14Z</dc:date>
    </item>
  </channel>
</rss>

