The situation
On SW1, VLAN 10 (192.168.10.0/24) gets its addresses from R1. Last week a visitor plugged a home router into a desk port: it handed out its own addresses and half the floor lost access. Lock down the access ports (Gi0/2 to Gi0/24) so it can't happen again, without breaking the real users. Gi0/1 is the uplink to R1.
- 1. Real server: Offers from R1 arrive on Gi0/1, the trusted port, and are forwarded.
- 2. Rogue server: Offers arriving on Gi0/7, an untrusted port, are dropped by DHCP snooping.
Task 1: port security
Each desk has one PC. Learn it automatically, keep it in the configuration, and shut the port if another device appears.
Show the configuration
interface range GigabitEthernet0/2 - 24
switchport mode access
switchport access vlan 10
switchport port-security
switchport port-security maximum 1
switchport port-security mac-address sticky
switchport port-security violation shutdownPort security needs a static access (or trunk) mode; it is refused on a dynamic port. maximum 1 and violation shutdown are the defaults, typed here so the intent is clear. Sticky MACs are added to the running configuration: save it to keep them after a reload.
SW1#show port-security interface GigabitEthernet0/5 Port Security : Enabled Port Status : Secure-up Violation Mode : Shutdown Aging Time : 0 mins Aging Type : Absolute SecureStatic Address Aging : Disabled Maximum MAC Addresses : 1 Total MAC Addresses : 1 Configured MAC Addresses : 0 Sticky MAC Addresses : 1 Last Source Address:Vlan : 0200.0000.0105:10 Security Violation Count : 0
Task 2: DHCP snooping
Show the configuration
ip dhcp snooping
ip dhcp snooping vlan 10
no ip dhcp snooping information option
!
interface GigabitEthernet0/1
ip dhcp snooping trust
!
interface range GigabitEthernet0/2 - 24
ip dhcp snooping limit rate 15Snooping is on globally and for VLAN 10. Only Gi0/1 is trusted, so server messages (offers, acks) from any other port are dropped. Option 82 insertion is turned off because R1 is not a relay agent expecting it. The rate limit stops a client flooding DHCP requests.
SW1#show ip dhcp snooping binding MacAddress IpAddress Lease(sec) Type VLAN Interface ------------------ --------------- ---------- ------------- ---- -------------------- 02:00:00:00:01:05 192.168.10.21 86211 dhcp-snooping 10 GigabitEthernet0/5 02:00:00:00:01:06 192.168.10.22 86198 dhcp-snooping 10 GigabitEthernet0/6 Total number of bindings: 2
Task 3: Dynamic ARP Inspection
Show the configuration
ip arp inspection vlan 10
!
interface GigabitEthernet0/1
ip arp inspection trustARP packets on untrusted ports are checked against the DHCP snooping bindings; a reply claiming an IP that a different MAC leased is dropped. Devices with static addresses need ARP ACLs, or their ARP is dropped.
Task 4: what happens when…
…the visitor plugs the home router into Gi0/7?
Show the answer
Gi0/7 learned a PC earlier (sticky). The home router has a different MAC, so port security sees a violation and the port goes err-disabled. Even before that, its DHCP offers would be dropped because Gi0/7 is untrusted.
SW1#show interfaces status err-disabled Port Name Status Reason Err-disabled Vlans Gi0/7 err-disabled psecure-violation
Recovery: remove the device, then shutdown and no shutdown on Gi0/7. Or let errdisable recovery cause psecure-violation bring it back automatically after the recovery interval (300 seconds by default).
…a user replaces their PC?
Show the answer
Same violation: the sticky MAC belongs to the old PC. Remove it with no switchport port-security mac-address sticky 0200.0000.0107 (or clear port-security sticky interface Gi0/7), then recover the port.
Fix the mistakes
Mistake 1
After enabling DHCP snooping, no PC gets an address at all.
Show diagnosis
Gi0/1 was not made trusted, so the real server's offers are dropped too. Fix: ip dhcp snooping trust on Gi0/1.
Mistake 2
switchport port-security is rejected with "Command rejected: GigabitEthernet0/9 is a dynamic port".
Show diagnosis
The port is still in dynamic (DTP) mode. Fix: switchport mode access first.
Mistake 3
After DAI is enabled, the network printer with a static IP address stops working.
Show diagnosis
The printer never used DHCP, so it has no binding and its ARP replies are dropped. Fix: an ARP ACL for its IP and MAC applied with ip arp inspection filter, or move the printer to DHCP with a reservation so it gets a binding.
Check yourself
Port security is set to violation restrict and a second MAC appears. What happens?
Which port should be trusted for DHCP snooping on SW1?
What does Dynamic ARP Inspection compare ARP packets against?