cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
146
Views
1
Helpful
2
Replies

DHCP Snooping Best Practices on Access Switches

Hi Everyone,

In enterprise LANs, I usually enable DHCP snooping for security — but it sometimes causes issues if trust is not configured correctly on uplinks.

Quick questions:

  1. Do you enable DHCP Snooping by default on all access VLANs?
  2. Do you also use IP Source Guard and Dynamic ARP Inspection along with it?
  3. Any common mistakes that can cause client IP assignment issues?

Appreciate your input!

Thanks

2 Replies 2

Hello,

In terms of DHCP snooping being a L2 security technology we configure it on mainly user VLANs such as PCs, VoIP phones, VTCs, printers etc. since those are the main VLANs that get DHCP addresses. Server VLANs or devices that have static IPs usually don’t get the snooping activated on that vlan.

ARP inspection and source guard are also applied as addition security measures.

Our main issue has been identifying trusted interfaces. That will cause client DHCP issues if not configured correctly.

 

Hope that helps

-David