09-30-2025 07:18 PM
Hi Everyone,
In enterprise LANs, I usually enable DHCP snooping for security — but it sometimes causes issues if trust is not configured correctly on uplinks.
Appreciate your input!
Thanks
10-01-2025 02:50 AM
Hello,
In terms of DHCP snooping being a L2 security technology we configure it on mainly user VLANs such as PCs, VoIP phones, VTCs, printers etc. since those are the main VLANs that get DHCP addresses. Server VLANs or devices that have static IPs usually don’t get the snooping activated on that vlan.
ARP inspection and source guard are also applied as addition security measures.
Our main issue has been identifying trusted interfaces. That will cause client DHCP issues if not configured correctly.
Hope that helps
-David
10-01-2025 04:08 AM
It all depends on the deployment and model you'reThe using :
guide below gives you an indication of what ports you need to trust and untrust :
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide