 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Network technologies and trends &#187; Configuring DHCP Snooping</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/network-technologies/tag/configuring-dhcp-snooping/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/network-technologies</link>
	<description></description>
	<lastBuildDate>Wed, 15 May 2013 18:52:38 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>How to configure DHCP Snooping in a Cisco Catalyst Switches.</title>
		<link>http://itknowledgeexchange.techtarget.com/network-technologies/how-to-configure-dhcp-snooping-in-a-cisco-catalyst-switches/</link>
		<comments>http://itknowledgeexchange.techtarget.com/network-technologies/how-to-configure-dhcp-snooping-in-a-cisco-catalyst-switches/#comments</comments>
		<pubDate>Sat, 22 Nov 2008 12:56:06 +0000</pubDate>
		<dc:creator>Yasir Irfan</dc:creator>
				<category><![CDATA[802.1 Q]]></category>
		<category><![CDATA[CCNP]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Cisco 2950]]></category>
		<category><![CDATA[Cisco 2960]]></category>
		<category><![CDATA[Cisco 3560]]></category>
		<category><![CDATA[Cisco 3560-E]]></category>
		<category><![CDATA[Cisco 3750-E]]></category>
		<category><![CDATA[Cisco 6500]]></category>
		<category><![CDATA[Cisco 6500 Series Catalyst Switch]]></category>
		<category><![CDATA[Cisco 6503]]></category>
		<category><![CDATA[Cisco Catalyst 6503-E Switch]]></category>
		<category><![CDATA[Cisco Catalyst 6506-E Switch]]></category>
		<category><![CDATA[Cisco Catalyst 6509-E Switch]]></category>
		<category><![CDATA[Cisco Catalyst 6509-V-E Switch]]></category>
		<category><![CDATA[Cisco Catalyst 6513 Switch]]></category>
		<category><![CDATA[Cisco IOS]]></category>
		<category><![CDATA[Cisco Learning]]></category>
		<category><![CDATA[Cisco Systems]]></category>
		<category><![CDATA[Cisco Tips]]></category>
		<category><![CDATA[Configuring DHCP Snooping]]></category>
		<category><![CDATA[DHCP]]></category>
		<category><![CDATA[DHCP Snooping]]></category>
		<category><![CDATA[HSRP]]></category>
		<category><![CDATA[IOS commands]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Routing and Switching]]></category>
		<category><![CDATA[Server Security]]></category>
		<category><![CDATA[Switches]]></category>
		<category><![CDATA[Switching]]></category>
		<category><![CDATA[Trunk Ports]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/network-technologies/how-to-configure-dhcp-snooping-in-a-cisco-catalyst-switches/</guid>
		<description><![CDATA[ So here we go, with the configuration of DHCP snooping on a Cisco Switch. This feature protects the network by allowing the Cisco Switches to accept DHCP response message only from the authorized servers connected to the trusted interfaces in a Cisco Switch. All Switch to  Switch connections are configured as 802.1 1Q Trunk ports. IP [...]]]></description>
				<content:encoded><![CDATA[<p> <span><font face="Calibri">So here we go, with the configuration of DHCP snooping on a Cisco Switch. This feature protects the network by allowing the Cisco Switches to accept DHCP response message only from the authorized servers connected to the trusted interfaces in a Cisco Switch.</font></span></p>
<p><span><font face="Calibri"><a href="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/58/files/2008/11/dhcp-snooping1.jpg" title="DHCP"><img src="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/58/files/2008/11/dhcp-snooping1.jpg" alt="DHCP" /></a></font></span></p>
<p><span></span><span><font face="Calibri"><span><font face="Calibri">All Switch to  Switch connections are configured as 802.1 1Q Trunk ports.</font></span></font></span></p>
<p><span><font face="Calibri"><span></span></font></span><span><font face="Calibri"><span><font face="Calibri"><span><font face="Calibri">IP Address and HSRP Details for the Core Switches</font></span><span><font face="Calibri"> </font></span></font></span></font></span><span><font face="Calibri"> </font></span><span><font face="Calibri"><span><font face="Calibri"><a href="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/58/files/2008/11/dhcp-snooping2.jpg" title="DHCP 1"><img src="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/58/files/2008/11/dhcp-snooping2.jpg" alt="DHCP 1" /></a></font></span></font></span><span><font face="Calibri"><span><font face="Calibri">From the above scenario we have two Cisco 6513 Series Switches as a Core/ Distribution with three VLANS one for management of Switches VLAN 50,VLAN 100 for all the servers and VLAN 101 for clients. Two Cisco 3560 Series Switches as Server Farm Switches and a Cisco 3560 Series Switch as an Access Switch.</font></span><span><font face="Calibri">There are two DHCP servers with an IP address 10.0.1.100 and 10.0.1.101 connected with Server Farm Switches with HP NIC teaming. We configure DHCP Snooping based on above scenario.</font></span><span><font face="Calibri"> </font></span></p>
<p></font></span><span></span><span><span><font face="Calibri">The first step to configure DHCP Snooping is to turn on DHCP snooping in all Cisco Switches using the “ip dhcp snooping” command.</font></span><span><font face="Calibri"> </font></span></span></p>
<p><span><span></span></span><span><span><font face="Calibri">All Cisco Switches (config)#ip dhcp snooping</font></span><span><font face="Calibri"> </font></span><span><span></span></span></span><span> </span><span><span><font face="Calibri">Second step is to configure the trusted interfaces, from the above scenario all trunk ports are configured as trusted ports as well as the interfaces G0/7,(ITKESF01 50.0.0.6), <span> </span>G0/17,(ITKESF02 50.0.0.7), <span> </span>G0/9 ITKESF01 50.0.0.6)<span>  </span>and G0/18 ITKESF02 50.0.0.7)<span>  </span>connected to DHCP servers with IP 10.0.1.100 and 10.0.1.101.</font></span></span><span><span></span><span><font face="Calibri"> </font></span><span><span><font face="Calibri">Lets configure all trunk ports in ITKEBB01</font></span><a title="OLE_LINK4" name="OLE_LINK4"></a><a title="OLE_LINK3" name="OLE_LINK3"></a><span><span><font face="Calibri"> </font></span></span></span></p>
<p></span><span><span><span></span></span></span></p>
<p><span><span><span><font face="Calibri">ITKEBB01(config)#interface range<span>  </span>gigabitEthernet 3/21 &#8211; 23</font></span></span></span></p>
<p><span><span><span></span></span><span><span><span><font face="Calibri">ITKEBB01 (config-if)#ip dhcp snooping trust</font></span></span></span><span><span><span><font face="Calibri"> </font></span></span></span></span></p>
<p><span><span><span><span></span></span></span></span><span><span></span><span></span><span></span><span><span><font face="Calibri">Now let’s configure all trunk ports in ITKEBB02</font></span><span><font face="Calibri"> </font></span></span></span></p>
<p><span><span><span></span></span></span><span><span><font face="Calibri">ITKEBB02(config)#interface range<span>  </span>gigabitEthernet 3/21 &#8211; 23</font></span></span><span> </span><span><span></span><span><font face="Calibri">ITKEBB02 (config-if)#ip dhcp snooping trust</font></span><span><font face="Calibri"> </font></span></p>
<p></span><span></span><span><span><font face="Calibri">ITKEBB02 (config)#interface gigabitEthernet 3/16</font></span></span></p>
<p><span><span></span><span><font face="Calibri">ITKEBB02 (config-if)#ip dhcp snooping trust</font></span><span><font face="Calibri"> </font></span></span></p>
<p><span><span></span></span><span><span><font face="Calibri">Now let’s configure the trusted ports for the DHCP servers </font></span><span><font face="Calibri"> </font></span></span></p>
<p><span><span></span><span><span><font face="Calibri">ITKESF01(config)#interface gigabitEthernet 0/7</font></span></span></span></p>
<p><span><span><span></span><span><font face="Calibri">ITKESF01 (config-if)#ip dhcp snooping trust</font></span><span><font face="Calibri"> </font></span></span></span><span> </span></p>
<p><span></span><span><span></span><span><span><font face="Calibri">ITKESF01(config)#interface gigabitEthernet 0/17</font></span></span></span><span> </span><span><span><span></span><span><font face="Calibri">ITKESF01 (config-if)#ip dhcp snooping trust</font></span><span><font face="Calibri"> </font></span></span></p>
<p></span><span><span></span></span><span><span><font face="Calibri">ITKESF02(config)#interface gigabitEthernet 0/9</font></span></span></p>
<p><span><span></span><span><font face="Calibri">ITKESF02 (config-if)#ip dhcp snooping trust</font></span><span><font face="Calibri"> </font></span></span></p>
<p><span><span></span><span><span></span></span></span><span><span><font face="Calibri">ITKESF02(config)#interface gigabitEthernet 0/18</font></span></span><span> </span><span><span></span><span><font face="Calibri">ITKESF02 (config-if)#ip dhcp snooping trust</font></span><span><font face="Calibri"> </font></span></p>
<p></span><span></span><span><span><font face="Calibri">Now let’s configure the trunk ports <span> </span>Access Switch ITKEAS01</font></span><span><font face="Calibri"> </font></span></span></p>
<p><span><span></span></span><span><span><font face="Calibri">ITKEAS01(config)#interface range<span>  </span>gigabitEthernet 0/49 &#8211; 52</font></span></span></p>
<p><span><span></span><span><font face="Calibri">ITKEAS01 (config-if)#ip dhcp snooping trust</font></span><span><font face="Calibri"> </font></span><span><span></span></span></span><span> </span></p>
<p><span></span></p>
<p><span></span><span><span><font face="Calibri">Finally we are going to configure VLANS for DHCP snooping DHCP snooping will used on all the VLANs (VLAN 100 &amp; 101)except management VLAN 50 . Also we will limit the requests rate received in the Access Switch (ITKEAS01)</font></span><span><font face="Calibri"> </font></span></span><span> </span><span><span></span><span><span><font face="Calibri">ALL SWITCHES(config)# ip dhcp snooping VLAN 100,101</font></span><span><font face="Calibri"> </font></span></span></p>
<p></span><span><span></span></span><span><span><font face="Calibri">ITKEAS01(config)#interface range<span>  </span>gigabitEthernet 0/1 &#8211; 48</font></span></span></p>
<p><span><span></span></span><span><span></span><span><font face="Calibri">ITKEAS01 (config-if)#ip dhcp snooping limit rate 20</font></span></span><span> </span><span><span><a href="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/58/files/2008/11/dhcp-snooping3.jpg" title="DHCP2"></a></span></p>
<p></span><span></span><span><font face="Calibri">Displaying the DHCP snooping </font></span><span><font face="Calibri"> </font></span></p>
<p><span><a href="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/58/files/2008/11/dhcp-snooping3.jpg" title="DHCP2"><img src="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/58/files/2008/11/dhcp-snooping3.jpg" alt="DHCP2" /></a></span></p>
<p><span></span><span><span><font face="Calibri">For further reference please do check this </font><a target="_blank" href="http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SXF/native/configuration/guide/snoodhcp.html"><font face="Calibri">article from Cisco about DHCP snooping</font></a><font face="Calibri">.</font></span></span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/network-technologies/how-to-configure-dhcp-snooping-in-a-cisco-catalyst-switches/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
