cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1611
Views
0
Helpful
10
Replies

DHCP snooping issue

GMahendra
Level 1
Level 1

Hi guys

I am facing issue when i configured  Ip dhcp snooping  comman in c2960x ,3750 & 3650...

 

Issue : users/clients do not receive Ip address automatically after configuring the  ipIdhcp snooping  command.

 

Do you have any idea about this?

 

Kind regards,

Mahendra Gharbude

10 Replies 10

balaji.bandi
Hall of Fame
Hall of Fame

We need to know what is the version of IOS you running, and show us your configuration.

 

do you have any debug logs, when they enable ip dhcp snoop.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi,

iOS version is 15.2(2)E7 ,model- 2960x

Configuration on switch- Ip dhcp snooping vlan 1- 999

 

Currently snooping is disabled on switch.

 

Attached screenshot.

Hi,

iOS version is 15.2(2)E7 ,model- 2960x

Configuration on switch- Ip dhcp snooping vlan 1- 999

 

Currently snooping is disabled on switch.

 

Attached screenshot.

luis_cordova
VIP Alumni
VIP Alumni

Hi @GMahendra ,

 

Could you show us the settings you enter?
This tool is implemented to avoid attacks by fake DHCP services.
In addition, you must indicate which interfaces will be reliable, that is, by which interface if addresses can be received through DHCP.

 

Regards

Hello

Disable option 82 insertion on the access layer switches where snooping is applied also trust the switches uplinks then test again 

Sh ip dhcp snooping

No ip dhcp snooping information option 


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

Thanks Paul,

 

If I remove option 82 ,what will be impact in network. How is option 82 works?

 

What is command to enable the option 82 again in network.

 

 

Kind regards,

Mahendra

Hello

Its only applicable when dhcp snooping is enabled and as you have reported that some of your clients are not able to receive dhcp allocated after snooping is activated so the suggestion would be to try and disable option 82 on switches (3560's.3650's) that by default this feature on when snooping applied.

 

You can reapply it by simply  -  ip dhcp snooping information option

Please review this document - it will explain a lot clear then i ever can


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

Thanks Paul. I will try it and let you know.

Jaderson Pessoa
VIP Alumni
VIP Alumni

@GMahendra ,

 

 

Adding something else, dont forget to define and insert the command under the trusted interface that can able transport dhcp packets.

 

ip dhcp snooping trust

 

check it for more information: https://www.cisco.com/c/en/us/support/docs/smb/switches/cisco-small-business-300-series-managed-switches/smb5715-configure-dhcp-trusted-interface-settings-on-a-switch-throug.html

Jaderson Pessoa
*** Rate All Helpful Responses ***

Joseph W. Doherty
Hall of Fame
Hall of Fame
The two important things to remember are 1) insure you trust the links (and transits) from your valid DHCP server(s) and 2) if you have a downstream L3 device forwarding DHCP requests without DHCP snooping also enabled, you need to configure it special (that's where the option 82 stuff comes into play).
Review Cisco Networking for a $25 gift card