09-25-2023 05:20 AM
Hello,
is there an issue when we have WLC DHCP proxy mode and upstream switch with DHCP snooping enabled?
Based on docs, WLC in proxy mode changes giaddr field (and can insert option-82 as well) and switch ignores DHCP messages over untrusted ports if it has non-zero giaddr field or option-82 (like relay info inserted).
Then, it should be problematic for DHCP snooping enabled environment, right? We need to make trust WLC connected ports (which disables snooping checks for those ports, in reality) or configure L2 ports as ip dhcp relay trusted. Did anyone had
09-25-2023 05:53 AM - edited 09-25-2023 05:54 AM
snooping dictates where offer comes from not where discover comes from, so dont think this should be an issue
09-25-2023 06:50 AM
No, snooping has some checks for client messages as well.
For example, when you have access and distro switch with both snooping enabled where access inserts option82, then distro switch ignores client messages. We normally either remove option82 on access OR allow it on untrusted port on distro switch.
I assume then same happens in WLC, but can not get confirmation since I dont have WLC Lab
09-25-2023 07:16 AM - edited 09-25-2023 07:18 AM
you are right you have to have ip dhcp snooping information option allow-untrusted.
by default its disabled.
10-01-2023 03:58 PM
DHCP proxy only applies to the old AireOS based WLCs which are almost end of life. If you are designing for future then you should be looking at the 9800 series WLCs.
If you use 9800 series WLC as per the Best Practice guide (link below) then you should not configure SVI on the 9800 at all and leave the snooping/forwarding/relaying to the attached infrastructure. If you do configure SVI with helper address/dhcp relay then it will be doing standards based DHCP relay not DHCP proxy.
10-02-2023 11:42 AM
Thank you, but since it is DHCP relay then giaddr will be modified and infrastructure dhcp snooping enabled switch will ignore these messages over untrusted.
Seems, if it is not bridge mode then ip dhcp snooping trust is needed
10-02-2023 12:01 PM
Ip dhcp snooping trust toward wlc is not needed since the wlc is represent client here.
The modify of dhcp and add op82 is need I think.
Now
Wlc add op82 send to SW (with dhcp snooping) what you need is
Ip dhcp snooping information option allow-untrusted
Why untrust ? Since the port is untrust and wlc add op82 then this need.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide