Course menu

Course 13: Security FundamentalsLesson 2.4 (5 of 11 in this course)111 of 122 in the CCNA series

Lab: port security, DHCP snooping and DAI

Lock down access ports, stop rogue DHCP servers, add Dynamic ARP Inspection, and recover from the violations they cause.

Intermediate · 25 min read

What you will learn

After this lesson, you can secure access ports with port security, enable DHCP snooping and Dynamic ARP Inspection for VLAN 10, and recover from the violations they cause.

  • Port security
  • DHCP snooping
  • DAI
  • err-disabled recovery

Layer 2 security features are switch features that check what end devices send before forwarding it: port security limits the MAC addresses on a port, DHCP snooping only accepts DHCP server messages on trusted ports and records who got which address, and Dynamic ARP Inspection drops ARP replies that don't match those records.

In simple terms: The switch stops trusting everything plugged into it: only known devices on each port, only the real DHCP server handing out addresses, and no lying about who owns an IP address.

The situation

On SW1, VLAN 10 (192.168.10.0/24) gets its addresses from R1. Last week a visitor plugged a home router into a desk port: it handed out its own addresses and half the floor lost access. Lock down the access ports (Gi0/2 to Gi0/24) so it can't happen again, without breaking the real users. Gi0/1 is the uplink to R1.

R1DHCP server · 192.168.10.1SW1Gi0/1 uplink (trusted)PC1Gi0/5 · VLAN 10PC2Gi0/6 · VLAN 10Rogue routerGi0/7 · own DHCP
  1. 1. Real server: Offers from R1 arrive on Gi0/1, the trusted port, and are forwarded.
  2. 2. Rogue server: Offers arriving on Gi0/7, an untrusted port, are dropped by DHCP snooping.

Task 1: port security

Each desk has one PC. Learn it automatically, keep it in the configuration, and shut the port if another device appears.

Show the configuration
interface range GigabitEthernet0/2 - 24 switchport mode access switchport access vlan 10 switchport port-security switchport port-security maximum 1 switchport port-security mac-address sticky switchport port-security violation shutdown

Port security needs a static access (or trunk) mode; it is refused on a dynamic port. maximum 1 and violation shutdown are the defaults, typed here so the intent is clear. Sticky MACs are added to the running configuration: save it to keep them after a reload.

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show port-security interface GigabitEthernet0/5
Port Security              : Enabled
Port Status                : Secure-up
Violation Mode             : Shutdown
Aging Time                 : 0 mins
Aging Type                 : Absolute
SecureStatic Address Aging : Disabled
Maximum MAC Addresses      : 1
Total MAC Addresses        : 1
Configured MAC Addresses   : 0
Sticky MAC Addresses       : 1
Last Source Address:Vlan   : 0200.0000.0105:10
Security Violation Count   : 0

Task 2: DHCP snooping

Show the configuration
ip dhcp snooping ip dhcp snooping vlan 10 no ip dhcp snooping information option ! interface GigabitEthernet0/1 ip dhcp snooping trust ! interface range GigabitEthernet0/2 - 24 ip dhcp snooping limit rate 15

Snooping is on globally and for VLAN 10. Only Gi0/1 is trusted, so server messages (offers, acks) from any other port are dropped. Option 82 insertion is turned off because R1 is not a relay agent expecting it. The rate limit stops a client flooding DHCP requests.

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show ip dhcp snooping binding
MacAddress          IpAddress        Lease(sec)  Type           VLAN  Interface
------------------  ---------------  ----------  -------------  ----  --------------------
02:00:00:00:01:05   192.168.10.21    86211       dhcp-snooping   10    GigabitEthernet0/5
02:00:00:00:01:06   192.168.10.22    86198       dhcp-snooping   10    GigabitEthernet0/6
Total number of bindings: 2
The binding table: which MAC got which IP on which port. Dynamic ARP Inspection uses it next.

Task 3: Dynamic ARP Inspection

Show the configuration
ip arp inspection vlan 10 ! interface GigabitEthernet0/1 ip arp inspection trust

ARP packets on untrusted ports are checked against the DHCP snooping bindings; a reply claiming an IP that a different MAC leased is dropped. Devices with static addresses need ARP ACLs, or their ARP is dropped.

Task 4: what happens when…

…the visitor plugs the home router into Gi0/7?

Show the answer

Gi0/7 learned a PC earlier (sticky). The home router has a different MAC, so port security sees a violation and the port goes err-disabled. Even before that, its DHCP offers would be dropped because Gi0/7 is untrusted.

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show interfaces status err-disabled
Port      Name               Status       Reason               Err-disabled Vlans
Gi0/7                        err-disabled psecure-violation

Recovery: remove the device, then shutdown and no shutdown on Gi0/7. Or let errdisable recovery cause psecure-violation bring it back automatically after the recovery interval (300 seconds by default).

…a user replaces their PC?

Show the answer

Same violation: the sticky MAC belongs to the old PC. Remove it with no switchport port-security mac-address sticky 0200.0000.0107 (or clear port-security sticky interface Gi0/7), then recover the port.

Fix the mistakes

Mistake 1

After enabling DHCP snooping, no PC gets an address at all.

Show diagnosis

Gi0/1 was not made trusted, so the real server's offers are dropped too. Fix: ip dhcp snooping trust on Gi0/1.

Mistake 2

switchport port-security is rejected with "Command rejected: GigabitEthernet0/9 is a dynamic port".

Show diagnosis

The port is still in dynamic (DTP) mode. Fix: switchport mode access first.

Mistake 3

After DAI is enabled, the network printer with a static IP address stops working.

Show diagnosis

The printer never used DHCP, so it has no binding and its ARP replies are dropped. Fix: an ARP ACL for its IP and MAC applied with ip arp inspection filter, or move the printer to DHCP with a reservation so it gets a binding.

Check yourself

Predict · scenario 1

Port security is set to violation restrict and a second MAC appears. What happens?

Predict · scenario 2

Which port should be trusted for DHCP snooping on SW1?

Predict · scenario 3

What does Dynamic ARP Inspection compare ARP packets against?