Sections:
Overview:
Lab Topology
Scenario:
Rogue DHCP Effects
2 out the 4 PCs received an IP address from the rogue DHCP server
Engineering VLAN10
Finance VLAN20
MGMT VLAN60
Servers VLAN80
Active leases on rogue DHCP server switch.
Rogue DHCP Server Potential Consequences
Trusted vs Untrusted Ports
Overview
Trusted vs Untrusted Ports
DHCP Snooping Binding Table
Information Option 82
DHCP Snooping Configuration
HQ-Access-SW1
Enable DHCP Snooping globally and on specific VLANs.
Define trusted ports.
Disable information option 82 and verify DHCP binding table & statistics.
HQ-Distro-SW1
Enable DHCP Snooping globally and for specific VLANs in addition to defining trusted ports.
Disable information option 82 and verify DHCP Snooping statistics.
HQ-Distro-SW2
Enable DHCP Snooping globally and for specific VLANs in addition to defining trusted ports.
Disable information option 82 and verify DHCP Snooping statistics.
HQ-Core-SW1
Enable DHCP Snooping globally and for specific VLANs in addition to defining trusted ports.
Disable information option 82 and verify DHCP binding table & statistics.
DHCP Snooping Additional Features
DHCP Snooping Rate Limit
HQ-Access-SW1
Example of HQ-Access-SW1 dropping DHCP packets when rate limit exceeds.
HQ-Core-SW1