Comments on: DHCP Snooping ARP Inspection IP Source Guard https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/ technology, networking, virtualization and IP telephony Sat, 30 Oct 2021 18:15:39 +0000 hourly 1 https://wordpress.org/?v=6.8.3 By: DHCP Snooping, Dynamic ARP Inspection and IP Source Guard | Mike Pemberton's Blog https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-81564 Thu, 29 Jun 2017 07:19:24 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-81564 […] https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/ […]

]]>
By: Rafi https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-81029 Thu, 25 May 2017 11:45:57 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-81029 In reply to Rafi.

Hi,
I checked it again this time include Dhcp server and after i chcked it i realized that i IT gave me the wrong port.

Fixed it all works well.

Thanks
Rafi

]]>
By: Rafi https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-80975 Mon, 22 May 2017 08:21:05 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-80975 In reply to Michael McNamara.

Hi Michael,
Yes it’s really old :(

I don’t own the dhcp so i don’t know if the server sees the massage “discover”. (i can ask the it guy to give me access)
It’s L2 the client is broadcasting to the dhcp server.

Regards
Rafi

]]>
By: Michael McNamara https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-80939 Sat, 20 May 2017 13:02:12 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-80939 In reply to Rafi.

Hi Rafi,

That’s a really hold piece of hardware with some really old software you have there.

Is the DHCP server seeing the DHCP discover requests? Is this all Layer 2 or do you have DHCP relay enabled?

Good Luck!

]]>
By: Rafi https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-80936 Sat, 20 May 2017 10:22:01 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-80936 Hi Michael,

I tried to add dhcp snooping on nortel 8300 version 4.2.2.
Aftet i enabled it clients couldent get ip

This is how i enabled the dhcp snooping
– Enable in global
-Enable on specipic
– change the switch port of dhcp server
To trust (true)

Any idea ?

]]>
By: Network is down! Please help! https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-21699 Mon, 06 Jan 2014 15:20:03 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-21699 […] You’re already doing each of the previously listed items? Well you could look at the following additional steps. You can find additional detail in a blog post titled, DHCP Snooping ARP Inspection IP Source Guard. […]

]]>
By: Fabien B. https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-19239 Wed, 27 Nov 2013 07:57:58 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-19239 In reply to Michael McNamara.

Hi Michael,

Thanks fot the quick answer.

Software version is 5.6.0008, and since it’s a test configuration, I can’t really make update, since it’s supposed to be the same configuration as production switches…

I’ll try a more recent software to see if it’s a bug, and I’ll let you know.

]]>
By: Michael McNamara https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-19218 Wed, 27 Nov 2013 00:45:27 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-19218 In reply to Fabien B..

Hi Fabien,

What version of software?

I haven’t tested it myself in a L3 configuration, wondering if you’ve stumbled across a bug.

Cheers!

]]>
By: Fabien B. https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-19192 Tue, 26 Nov 2013 13:27:43 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-19192 Hello,

I’m currently trying to implement DHCP snoop and ARP inspection on a 4500 with L3 (RIP, dhcp-relay), and my IP phones can get an IP address, but are not entered in DHCP Snooping binding table, and then doesn’t work…

We already implemented those protocols on 4500 with only L2 protocols, and there’s no problem…

Do you have an idea ?

Fabien.

]]>
By: Ricardo Meireles https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-18939 Wed, 06 Nov 2013 10:20:52 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-18939 Hello Micheal,

When I set up DHCP-Snooping/DAI, 802.1x stop working without warning exactlly on the switch used for testing purposes. It turns out to be a coincidence. I’ve just upgraded the switch and now both features are working well.

]]>
By: Michael McNamara https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-18819 Wed, 09 Oct 2013 01:35:30 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-18819 In reply to Ricardo Meireles.

Hi Ricardo,

I haven’t used the combination myself personally… I would think 802.1x occurs well before any DHCP requests.

What exactly are you seeing?

Cheers!

]]>
By: Ricardo Meireles https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-18811 Mon, 07 Oct 2013 21:57:33 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-18811 Is DHCP-Snooping/DAI compatible with 802.1x?

I’m seeting up these features together with some issues

]]>
By: karky https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-13859 Fri, 08 Feb 2013 18:45:56 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-13859 About Dynamic ARP Inspection, you can use DHCP Snooping External Save. Every 5 minutes the table is saved on a tftp server. If the stack reboot, the table is loaded.

]]>
By: IJdod https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-12954 Fri, 25 Jan 2013 15:03:05 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-12954 Cheers. Something I’ll have to test in the lab, then. I would suspect it works, otherwise there wouldn’t be much point to it… Would have been nice if Avaya documented that bit just a little bit better :D.

]]>
By: Michael McNamara https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-12950 Fri, 25 Jan 2013 14:39:16 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-12950 In reply to IJdod.

Hi IJdo,

I believe DHCP Option 82 will work regardless if the switch is configured as a Layer 3 router or just a Layer 2 access/edge switch.

Cheers!

]]>
By: IJdod https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-12925 Fri, 25 Jan 2013 11:39:32 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-12925 Interesting post, thank you.

Does the vlan interface actually have to do the routing for the vlan to be able to use option 82? In other words: does it work with a router upstream (which does the actual DHCP relay for that vlan as well) from the access switch?

]]>
By: Michael McNamara https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-12646 Wed, 23 Jan 2013 17:21:11 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-12646 In reply to Will.

Hi Will,

As you alluded to these features require some thought and evaluation before deploying. I will raise this point as well, if you want to move a port to a different you need to disable IP Source Guard before you can change the VLAN assignment.

Thanks for the comment!

]]>
By: Will https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-12453 Tue, 22 Jan 2013 19:11:07 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-12453 Michael,

This post was excellent. Thanks a lot.

I remember when a peer turned on arp inspection (to try and fix a broadcast storm) and took down the entire network. i.e. – do not enable any of the above unless you understand the impact

]]>
By: Michael McNamara https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-12141 Mon, 21 Jan 2013 03:11:35 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-12141 In reply to Frank.

Thanks for the comment Frank!

I don’t think we’ll be deploying IPv6 on the internal production network anytime soon. We have plans to offer IPv6 on our Internet accessible networks and on our DMZ networks but no real need for IPv6 on the actual internal network. I can’t imagine the stares I’ll get from all the healthcare vendors regarding IPv6, they probably don’t even have IPv6 on their product or support roadmaps.

These features make a great argument for doing manual (reserved) DHCP IP address assignments for almost everything (if possible). The more devices using DHCP the less administrative overhead you’ll need to content with in managing the DHCP snooping tables. I believe the DHCP snooping table has a limit of 1024 records as of 6.2 software for the Ethernet Routing Switch 5000 series so you can’t really implement a single network wide table.

Cheers!

It might be w

Cheers!

]]>
By: Frank https://blog.michaelfmcnamara.com/2013/01/dhcp-snooping-arp-inspection-ip-source-guard/comment-page-1/#comment-12089 Sun, 20 Jan 2013 20:59:04 +0000 http://blog.michaelfmcnamara.com/?p=3436#comment-12089 We are in the process of rolling out these features across all of our edge ports, as hardware refreshes allow it. It’s already cut down on impact from various broken/misconfigured, especially in residential buildings.

One more note to add – don’t forget to pester your vendors, whoever they may be to get full feature parity in the IPv6 space. We need RA guard and NDP inspection, or we’re going to have the same old problem re-appearing as soon as we roll out v6!

]]>