06-05-2018 09:46 AM - edited 02-21-2020 07:51 AM
Please, can we configure DHCP Snooping and IP Source Guard on a Distribution Switch or is it only on access level that these can work?
The Scenario here is: We have Cisco 2960X as our distribution switches with VLANs on it for more than 50 subnets at different locations. The router that does the routing and also serves as our DHCP is connected to this switch. Configured DHCP Snooping on the switch but once IP source guard is configured, the DHCP stopped working. Note that the ports on this switch is connected to the FMC of each subnet and the switches at these subnets are not catalyst, just ordinary switch. We want to be able to stop malicious users hijacking sessions of users by stealing the IP and assigning it as static IP on their systems. How can we go about this? Thank you.
06-05-2018 04:48 PM
Hi,
Dhcp snooping and IP source guard should work on the distribution switch.
You will need to configure the following:
Thanks
John
06-06-2018 01:25 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide