← All lab tasks Security Fundamentals Fix · Medium ~15 min · 3 devices · 5 tasks · CCNA v2.0
DHCP snooping: fix the globally disabled feature and the wrong trusted port SW1 sits between the DHCP server on Gi0/23 and the clients on Fa0/1 through Fa0/10. The engineer before you enabled snooping only partially: it is off globally, VLAN 10 was never enrolled, Fa0/1 was mistakenly marked trusted and Gi0/23 (the real server port) is still untrusted. The client DISCOVER packet is being dropped. Make the server uplink trusted and clients untrusted so legitimate DHCP flows through.
SW1 Gi0/23 -> DHCP-SRV (real DHCP server, 10.10.0.50) SW1 Fa0/1 -> PC1 (client, VLAN 10) Clients in VLAN 10 (10.10.0.0/24)
Tasks ○ Enable DHCP snooping globally: ip dhcp snooping ○ Enroll VLAN 10: ip dhcp snooping vlan 10 ○ Mark the server uplink Gi0/23 as trusted ○ Remove the trust on Fa0/1 (clients must be untrusted) ○ Rate-limit DHCP on Fa0/1 to 10 pps: ip dhcp snooping limit rate 10 ✓ Network fixed.
Snooping is on, VLAN 10 is enrolled, server port trusted, clients untrusted and rate-limited. Legitimate DHCP flows; rogue DHCP from a client port would now be dropped.
Hints (open one at a time) Hint 1: where to start Run show ip dhcp snooping. If "DHCP snooping is enabled" shows No, you need both ip dhcp snooping globally and ip dhcp snooping vlan 10.
Hint 2: trust direction Trust is applied under each interface with ip dhcp snooping trust. The ONLY port that should be trusted is the one toward the real DHCP server. Everything client-facing stays untrusted.
Hint 3: remove old trust Under Fa0/1 run no ip dhcp snooping trust. Without this, a client could still send OFFER / ACK packets that snooping would honor.
Full solution SW1# configure terminal
SW1(config)# ip dhcp snooping
SW1(config)# ip dhcp snooping vlan 10
SW1(config)# interface Gi0/23
SW1(config-if)# ip dhcp snooping trust
SW1(config-if)# exit
SW1(config)# interface Fa0/1
SW1(config-if)# no ip dhcp snooping trust
SW1(config-if)# ip dhcp snooping limit rate 10
SW1(config-if)# end
SW1# show ip dhcp snoopingThe binding table show ip dhcp snooping binding populates after the client gets a real ACK. Dynamic ARP Inspection in the same VLAN would then use that table to validate ARP.