Permits server replies only from trusted ports and builds a binding table from legitimate leases.
CCNA focus: Trust only the infrastructure-facing ports that truly need it. An incorrect trust boundary can either block valid service or allow an attacker to bypass inspection.
02 // Building blocks
Know what each part does.
01
DHCP snooping
Permits server replies only from trusted ports and builds a binding table from legitimate leases.
02
DAI
Validates ARP messages using trusted information such as the DHCP snooping binding table.
03
Port security
Limits which source MAC addresses may use an access port and defines violation action.
Drops violating frames and increments a counter without shutting the port.
Restrict
Drops and logs/counts violations without err-disabling the port.
Shutdown
Err-disables the port on violation; the common default.
Sticky
Dynamically learned secure MAC addresses are added to the running configuration.
04 // Access switch baseline
Access switch baseline.
SW1(config)# ip dhcp snoopingSW1(config)# ip dhcp snooping vlan 10SW1(config)# ip arp inspection vlan 10SW1(config)# interface gigabitEthernet 0/1SW1(config-if)# ip dhcp snooping trustSW1(config-if)# ip arp inspection trustSW1(config)# interface gigabitEthernet 0/10SW1(config-if)# switchport port-securitySW1(config-if)# switchport port-security maximum 2SW1(config-if)# switchport port-security mac-address stickySW1# show ip dhcp snooping binding
Read the example from top to bottom, then verify the resulting state. Configuration is only complete when the output matches the intended design.
05 // Exam and troubleshooting
Turn facts into a method.
Drops violating frames and increments a counter without shutting the port.
Drops and logs/counts violations without err-disabling the port.
Err-disables the port on violation; the common default.
Dynamically learned secure MAC addresses are added to the running configuration.
Exam checkpoint: Trust only the infrastructure-facing ports that truly need it. An incorrect trust boundary can either block valid service or allow an attacker to bypass inspection.
06 // Check yourself
Layer 2 Security quiz.
1. What table does DHCP snooping build?
2. What information can DAI use to validate ARP?
3. Which ports should usually be DHCP snooping trusted?
4. Which port-security mode err-disables the port by default?