cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
381
Views
0
Helpful
5
Replies

Untrusted DHCP

Andy White
Level 3
Level 3

Hello,

We had a user put a home router on our network as it had a hub, however the router had DHCP enabled so we started to get users phone up saying they had connectivity issues.  It took me ages to find out there was another DHCP device on the network.  Firstly how can I stop this and secondly how could I of located this issue quicker?

We use 2960s, 3560s and 3750s.

Thanks

1 Accepted Solution

Accepted Solutions

You need DHCP-Snooping:

http://www.cisco.com/en/US/docs/switches/lan/catalyst2960/software/release/12.2_55_se/configuration/guide/swdhcp82.html

With that you mark your uplinks as trusted and only on these links the DHCP-Answers are allowed.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

View solution in original post

5 Replies 5

Peter Paluch
Cisco Employee
Cisco Employee

Andy,

DHCP Snooping is your answer, definitely. Are you aware of this feature? See

http://www.cisco.com/en/US/docs/switches/lan/catalyst2960/software/release/15.0_2_se/configuration/guide/swdhcp82.html

Best regards,

Peter

You need DHCP-Snooping:

http://www.cisco.com/en/US/docs/switches/lan/catalyst2960/software/release/12.2_55_se/configuration/guide/swdhcp82.html

With that you mark your uplinks as trusted and only on these links the DHCP-Answers are allowed.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

Hello,

I couldn't get that URL to work.

Is this VMPS that I have just noticed coudl be a solution?

Regards

Hi,

just get rid of the partner subdirectory in the url and it will be functional.

No VMPS is not a solution, this is for dynamic vlan port assignment not for mitigating rogue dhcp servers.

You definitely need the DHCP snooping feature that Peter and Karsten told you about before.

Regards.

Alain

Don't forget to rate helpful posts.

Don't forget to rate helpful posts.

just removed the "partner" in the link ... I always forget that when posting links ...

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

Review Cisco Networking for a $25 gift card