cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
759
Views
0
Helpful
7
Replies

IP DHCP SNOOPING on CBS 350 24P-4G

ahmedaqsa
Level 1
Level 1

I activated dhcp snooping on CBS 350 switch but nothing happened .

I choose gi24 port as trusted port but nothing happened the switch still accept dhcp on the other ports.

I want the optimum solution and the right syntax which activate dhcp snooping on the switch and work correctly 

7 Replies 7

marce1000
VIP
VIP

 

  - Check current state of your dhcp snooping configuration with :  show ip dhcp snooping

 M.

 



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

ahmedaqsa
Level 1
Level 1

DHCP snooping is Enabled
DHCP snooping is configured on following VLANs: 1
DHCP snooping database is Disabled
Relay agent Information option 82 is Disabled
Option 82 on untrusted port is forbidden
Verification of hwaddr field is Enabled

Interface Trusted
----------- ------------
gi24 Yes

 

                       >...DHCP snooping database is Disabled
  This and the lines beneath seems indicative of the dhcp snooping not completely and or correctly configured , review 
           https://www.cisco.com/c/en/us/td/docs/switches/lan/csbms/CBS_250_350/CLI/cbs-350-cli-/dhcp-snooping-commands.html
               Check the command sequence , and or review your settings accordingly , 

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

ahmedaqsa
Level 1
Level 1

if there are anyone here , tried before to put DHCP snooping on CBS 350 24P-4G .

Please give us the feedback to check our configuration 

 

Hi @ahmedaqsa 

Can you share the config?  show running-config would be nice.

images (1).png

 I think you misunderstanding the dhcp snooping concept' 

Both trust and un trust (defualt mode of port) pass dhcp message but which message.

KJK99
Level 3
Level 3

@ahmedaqsa 

I have the DHCP snooping enabled on a couple of my CBS350-8MGP-2X access switches. The output of ‘show ip dhcp snooping’ from your switch looks fine to me. The line showing the status of the DHCP snooping database is really about its backup database, not the runtime database itself.

Just to be sure, you make ‘trusted’ the port where your DHCP server is connected to, not the ports where your DHCP clients are connected. Those ports should remain untrusted. You also need to enable snooping on your vlans.

Here’s the DHCP snooping configuration from one of my switches.

interface Port-Channel1
description MSW7LAG
ip dhcp snooping trust
switchport mode general
switchport general allowed vlan add 60,70,80-81,90 tagged
switchport general allowed vlan add 1 untagged

ip dhcp snooping
ip dhcp snooping vlan 1
ip dhcp snooping vlan 60
ip dhcp snooping vlan 70
ip dhcp snooping vlan 80
ip dhcp snooping vlan 90

Kris K