Skip to main content
PacketMentor logo
Open menu
← All lab tasks
Security Fundamentals Fix · Medium ~15 min · 3 devices · 5 tasks · CCNA v2.0

DHCP snooping: fix the globally disabled feature and the wrong trusted port

SW1 sits between the DHCP server on Gi0/23 and the clients on Fa0/1 through Fa0/10. The engineer before you enabled snooping only partially: it is off globally, VLAN 10 was never enrolled, Fa0/1 was mistakenly marked trusted and Gi0/23 (the real server port) is still untrusted. The client DISCOVER packet is being dropped. Make the server uplink trusted and clients untrusted so legitimate DHCP flows through.

SW1 Gi0/23 -> DHCP-SRV (real DHCP server, 10.10.0.50)
SW1 Fa0/1 -> PC1 (client, VLAN 10)
Clients in VLAN 10 (10.10.0.0/24)
Topology
SW1DHCP-SRVPC1

Stuck on a lab, or not sure what to practice next?

Talk it through with a mentor on a free 20-minute call. We look at your lab, your exam date and your weak spots, and you leave with a plan.

Book a free session