cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2037
Views
0
Helpful
15
Replies

DHCP Snooping on Catalyst 9k platform

mifi
Level 1
Level 1

We migrated from Catalyst 6k5 to 9k platform and found that DHCP snooping works different on the new platform. I cannot find if it is a feature or bug. So far we had DHCP snooping only in access layer, not in core. After migration, the end hosts were not able to obtain IP addresses until we configured DHCP snooping for the client VLANs in the core switch as well.

 

To find out the root cause I built a lab:

[pc] -- [access sw] -- [core sw] -- [DHCP server]

 

In the first scenario the DHCP snooping was off on access and core switch. The DHCP server was first on the core switch then on the DHCP server. The client was obtaining IP.

 

In the second scenario I configured DHCP snooping on access switch for the pc VLAN.

The client was unable to get an IP, the dhcp snooping debug on access switch showed DHCPREQUESTs only.

 

In the third scenario I address DHCP snooping also on the core switch. The PC obtained IP immediately.

 

I am running recommended software 16.12.3 on core switch which is Cat 9500-24Q in the lab, in the production we have Cat 9500-24Y4C with IOS-XE 16.12.3a. 

 

Any ideas?

 

Thanks,

Michal

15 Replies 15

Hi,

 

the sad truth is, that I missed that command :D Now I check the configuration history I see ip dhcp relay information trust-all on the C6k as well. My bad!

 

Thanks for your tips!

 

M

Review Cisco Networking for a $25 gift card