10-27-2022 03:28 AM
Hello, need help, i have cisco 3650 switch configured with vlan 10 and vlan20 wich is dhcp server also for that vlans, there is rogue dhcp server connected on that switch in vlan 20, how can i block dhcp offers from that rogue server with DHCP snooping, thanks in advance.
10-27-2022 05:34 AM
I want to double check if local DHCP is work with dhcp snooping but
for your Q the answer is
config all port as untrust, this make offer from DHCP server drop and client receive only offer from your DHCP local pool.
again if I get any restrict of use dhcp local with dhcp snooping I will inform you.
10-27-2022 08:40 AM
Hello,
as far as I recall, when you enable DHCP snooping (globally or for one or more Vlans), all ports are untrusted by default. So that is basically all you have to do, enable it (globally or for the required Vlans)...
--> C3560(config)# ip dhcp snooping
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide