le 22-07-2022 10:18 AM - dernière modification le 22-07-2022 10:54 AM par Jimena Saez
Bonjour,
Je voudrais un coup de main pour configurer la surveillance DAI et DHCP sur cette configuration.
Il semble que j'ai tout fait correctement, mais lorsque je connecte un PC au SW-A, j'obtiens ce message :
%DHCP_SNOOPING-5-DHCP_SNOOPING_NONZERO_GIADDR: DHCP_SNOOPING drop message with non-zero giaddr or option82 value on untrusted port, message type: DHCP DISCOVER, MAC sa: 0010.11D2.E395
Pourtant l'option 82 est désactivée.
Merci d'avance.
Hello,
I would like a hand to set up DAI and DHCP snooping on this configuration.
It seems I have done everything right, but when I connect a PC to the SW-A, I get this message:
%DHCP_SNOOPING-5-DHCP_SNOOPING_NONZERO_GIADDR: DHCP_SNOOPING drop message with non-zero giaddr or option82 value on untrusted port, message type: DHCP DISCOVER, MAC sa: 0010.11D2.E395
Yet option 82 is disabled.
Thanks in advance.
Résolu ! Accéder à la solution.
le 24-07-2022 04:28 PM
PKT limitation
Port-channel not config with IP DHCP snooping nor IP AP inspection, and I try and you can not config it.
if the port member of Port-channel config is different than the port-channel config the unpredictable behave happened or even the PO failed "in real network".
try same config but
with PO between SW
the Access SW config with
no ip dhcp snooping information option <- this remove Op82 before send DHCP packet to Core SW
le 22-07-2022 10:48 AM
Can you share lab here,
I can not open zip file.
Share as text
le 22-07-2022 10:58 AM
Ok, i want to share it in text format, but how ?
le 22-07-2022 11:09 AM
le 22-07-2022 11:49 AM
incompatible with my PKT, Sorry.
if you want share as text.
le 22-07-2022 12:32 PM
anyway
you need this
no ip dhcp snooping verify no-relay-agent-address
le 24-07-2022 09:24 AM
Thks,
commands are not working.
I'm using PT V8.1.0.0722
le 24-07-2022 09:36 AM
OK, only draw of topolgy with note about config and do print screen and I will do lab and see
le 24-07-2022 09:50 AM
le 24-07-2022 11:08 AM
Im' trying to find issue,
When I use a DHCP server behind the 290, and trust the link port, it works correctly.
But when I use the 3650 us a DHCP, with the same configuration, is doest not works !!
le 24-07-2022 11:31 AM
I install PKT ver. 8 and see your lab now,
there are many think need to check.
I will update you after couple hours
le 24-07-2022 11:55 AM
Case1
PC-L2SW-L3SW
in L2SW you can config
DHCP snooping
no DHCP snooping information option
ARP inspect
L2SW-L3SW must be trust
L3SW
config SVI of VLAN
NO dhcp snooping
NO ARP inspect
HSRP
DHCP Pool
this WORK and I test it
Case2
L3SW config
DHCP snooping
DHCP Pool
here I need more time to check this issue
le 24-07-2022 04:28 PM
PKT limitation
Port-channel not config with IP DHCP snooping nor IP AP inspection, and I try and you can not config it.
if the port member of Port-channel config is different than the port-channel config the unpredictable behave happened or even the PO failed "in real network".
try same config but
with PO between SW
the Access SW config with
no ip dhcp snooping information option <- this remove Op82 before send DHCP packet to Core SW
le 24-07-2022 05:30 PM
Not 100% Sure that PKT limitation
the DHCP snooping with LOCAL DHCP Server is failed, that why the external DHCP Server success.
why not 100% sure because cisco statement that
DHCP SNOOPING must not run in VLAN that config with DHCP POOL LOCAL.
but let assume that any DHCP snooping can not work with Local DHCP Pool.
Découvrez et enregistrez vos notes préférées. Revenez pour trouver les réponses d'experts, des guides étape par étape, des sujets récents et bien plus encore.
Êtes-vous nouveau ici? Commencez par ces conseils. Comment utiliser la communauté Guide pour les nouveaux membres
Parcourez les liens directs de la Communauté et profitez de contenus personnalisés en français