📖 What is DHCP Snooping?
A security feature that mitigates DHCP spoofing by filtering untrusted DHCP messages and building a binding database of valid client IP-to-MAC assignments.
"Remember that by default, all switch ports are untrusted. You must manually configure 'ip dhcp snooping trust' on uplink ports pointing to your legitimate DHCP server!"
📚 Certification: Certified Network Associate (200-301)
🔑 What are the Key Concepts of DHCP Snooping?
- ▸ Mitigates DHCP spoofing
- ▸ Trusted vs Untrusted ports
- ▸ Builds a DHCP binding database
🎯 How does DHCP Snooping appear on the 200-301 Exam?
Configuring trust states on uplink ports connected to a legitimate DHCP server.
Troubleshooting a scenario where legitimate DHCP offers are being dropped by a switch.
❓ Frequently Asked Questions
Which ports should be configured as trusted for DHCP snooping?
Ports connected to valid DHCP servers and uplink ports connecting to other switches.
What information does the DHCP snooping binding database store?
It stores MAC addresses, IP addresses, lease times, binding types, VLAN numbers, and interface information for untrusted ports.