what is DHCP Snooping ? as its name is very cleared what is that, its an mechanism to control your network DHCP Servers, in the DHCP Snooping we define DHCP Server connected to which port or VLAN and then after enable DHCP Snooping, if Switch receive any DHCP DISCOVERY massage, just forward that to Trusted ports, and its very basic operation for block some attacks like man-in-the-middle, cause in the networks without DHCP Snooping everyone can respond to DHCP Client massage and get IP to them with custom information like different Gateway.
maybe ask yourself how it work !? its very simple, each frame came from un-trust port for DHCPDISCOVERY, switch forward it to only Trusted port and then when ACK Massage was send to client, switch register some information to DHCP-Snooping Database, this Info include: Client MAC Address, Lease Time, Switch Port,IP Address and VLAN.
This table was stored in Flash by default but as you know flash capacity is limited and maybe you have a big Network with a lot of workstations, you need another place for store this Database(this database is a flat file with simple format), if your Database was out of your switches, then if switch was fail, you have copies of your DHCP Snooping Data and can very easily recover them to new switches or as you know when switch was reloaded, all of here DHCP Snooping Database data be cleared, but if you have an external database, you can keep this data to unlimited next reboot.This Database can accessed by CISCO Switches via remote protocols like TFTP.
IP Source Guard and Dynamic ARP Inspection uses this Database entry to perform own filtering or any operation must to do.
All entry will be remain in this Database file ? NO ! when they removed ? in two situation items in DHCP Snooping was removed Automatically via switches, 1: When lease time was ended and if workstation at this time send another request to DHCP, DHCP Server get it maybe new IP Address, then switch store new information of that host.
2: when client or workstation send RELEASE frame to DHCP Server.
and you must remember this tips, DHCP Snooping doesn't store Host Information about Every Host on Trusted ports. and when you want to view Hosts Information from DHCP Snooping Database, you cant see any data entry from ports that are Trusted already.
By default DHCP Snooping is disabled and you can enable it via this commands:
2. ip dhcp snooping
After Enabling DHCP Snooping Globally, then now is time to configure DHCP Snooping on one or more VLAN,via this command:
ip dhcp snooping vlan [vlan-list]
DHCP snooping MAC address verification:
This feature by default is enabled and if any packet revived from untrust ports have different MAC Address to client MAC Address for when it get IP Address from DHCP Server, then all of there packet be dropped.
How to register a port as a Trust:
ip dhcp snoop trust
get overall information about your DHCP Snooping configuration and ports status
I am unable to get SMS sending to work using a EHWIC-4G-LTE in a 2900 series router.IP connectivity works fine with the cellular module and it can also receive SMS messages. Sending fails every time with the following error, both using E.164 and loca...
Hi Friends,I am new to SDWAN and try to impliment SDWAN LAB.Following is the my testing Lab topology. I found following in the main dash board. As per above topoogy patial WAN connectivity is observerd in the main dashboard.I just co...
Dear all, I have a simple configuration on PacketTracer 6.0.1 (an old version indeed) where I was playing with HSRP priorities but it does not seem to be working as expected. I have 3 routers configured with IP addresses R1= 192.168.1.1, R2 = 19...
I have been handed an ASR 901 10G from a new building takeover. Left in an IT closet.Not sure if I want to play with it or not. What do they do?How much will it cost to license any services on it? Can I reset it? (not clear how based on se...
Hello, PC is connected to a router, loopback is created and able to reach without any issues from PC but from the other router which is connected to same router it's not pinging. I know we need to configure routing protocol, default routing etc ...