Writers' Community!
Home Page Two Columnists Submit an Article FAQs Contact Author Login
Article Submission
We Need YOUR Articles!
We'll Promote Them for FREE!

Author Login

New Authors
Register Here


Now Serving 5,557 Authors
50,504 Quality Articles
& 3,680 Current Users Online!
Featured Authors
David Pekrul (972)
Robert Melaccio, Sr. (6,253)
Nicole Beurkens (184)
Mogama (11,388)
Jane Bullard (3,855)
Terry Mitchell (2,643)
Susan Thom (9,047)
Rodney Biamby (90)
Michael Ramzy (156)
Aaron Taylor (1,129)
Ronyae (1,286)
Joel Hendon (10,717)
Mike Fak (9,928)
Joel Hirschhorn (857)

View All Featured Authors
Most Recent
Computer Training

Why should you get Microsoft and Cisco Certification?

Windows Vista Sidebar, Gadgets, Easy Wireless Networking and Improved Back Features

CompTIA A+, Security+, Network+ Tutorial Ethernet Card Troubleshooting

CCNA, CCENT, CCNP Tutorial on Routers and Routing

CompTIA Security+ Article on Firewall Security Advantages and Firewall Functions

Microsoft Training Certifications

CCNA Security Exam Tutorial: When It's Good To Add Salt

Why Switch to Windows Vista

Free Cisco CCNA, CCENT, CCNP Certification Tutorial

Home » Categories » Computers & Networking » Technical Certification » Cisco CCNP BCMSN 642-812 Certification Exam Tutorial: DHCP Snooping » Printer Friendly

Cisco CCNP BCMSN 642-812 Certification Exam Tutorial: DHCP Snooping

Rated 3.5 out of 5
No Reader Ratings Available ?
Rate It  /  View Comments  /  View All Articles submitted by Chris Bryant CCIE 12933
Submitted Thursday, May 03, 2007
Chris Bryant CCIE 12933 (13,636)
The Bryant Advantage
Log in to become a member of Chris Bryant CCIE 12933's Fan Club!


An important part of passing the Cisco CCNP BCMSN exam and protecting your network from intruders is to recognize that even everyday protocols and services can work against us once that intruder is in our network.

It may be hard to believe, but something as innocent as DHCP can actually lead to trouble for your network. When a host sends out a DHCPDiscovery packet, it listens for DHCPOffer packets - and accepts the first Offer it gets!

Part of that DHCPOffer is the address to which the host should set its default gateway. What if a DHCP server that does not belong on our network - a rogue DHCP server - is placed on that subnet?

If that host uses the DHCPOffer from the rogue server, the host could end up using the rogue server as its default gateway or DNS server!

We can prevent this with DHCP Snooping. DHCP Snooping classifies interfaces as either trusted or untrusted.

DHCP messages received on trusted interfaces will be permitted to pass through the switch, but DHCP messages received on untrusted interface result in the interface itself being placed into err-disabled state.

By default, the switch considers all ports untrusted - which means we better remember to configure the switch to trust some ports when we enable DHCP Snooping!

First, we need to enable DHCP Snooping on the entire switch:

SW1(config)#ip dhcp snooping

To enable DHCP Snooping for a particular VLAN, use the ip dhcp snooping command.

SW1(config)#ip dhcp snooping vlan 4

Ports can then be configured as trusted with the ip dhcp snooping trust command.

SW1(config-if)#ip dhcp snooping trust

There are other options available with DHCP Snooping, and we’ll look at some of those in a future tutorial. DHCP Snooping is an important topic for your CCNP BCMSN exam, and it’s just as important in real-world networks!

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage, home of free CCNP exam and CCNA Certification tutorials, The Ultimate CCNA Study Package, and Ultimate CCNP Study Packages.

You can also visit his blog, which is updated several times daily with new Cisco certification articles, free tutorials, and daily CCNA / CCNP exam questions! Details are on the website.

For a FREE copy of his latest e-books, “How To Pass The CCNA" and “How To Pass The CCNP", just visit the website! You can also get FREE CCNA and CCNP exam questions every day!

Get your Microsoft Vista certification with The Bryant Advantage!






Reprint Rights

Log in to become a member of Chris Bryant CCIE 12933's Fan Club!

Comments on this article:
No comments yet.


Was this article helpful to you? Leave a Public Comment or Question:

 

This Article has been viewed 131 times.
Article added to SearchWarp.com on Thursday, May 03, 2007
View other articles written by Chris Bryant CCIE 12933 (13,636)


If you found this article interesting, you may want to check out:

Disclaimer:  All information on this site is provided for informational purposes only! By no means is any information presented herein intended to substitute for the advice provided to you by any health care or other professional or organization.


Today's Most Popular
Cisco Certification: The Definitive Guide To ARP, RARP, IARP, and Proxy ARP

Cisco CCNA Exam Tutorial: Five OSPF Details You Must Know!

Cisco CCNA Exam Tutorial: Split Horizon And Hub-And-Spoke Networks

CCNP / BCMSN Exam Tutorial: Spanning Tree Protocol Timers

Cisco CCNA Certification Exam Tutorial: Route Summarization

Cisco CCNA Exam Tutorial: What's A Collision Domain?

Cisco CCNA Certification: Everything You Need To Know About Telnet!

Cisco CCNA Certification: Showdown At The Transport Layer... TCP vs. UDP !

Cisco Certification: How Ethernet CSMA/CD Works

How To Become A CCNA (Cisco Certified Network Associate)

Home  |  Page Two  |  FAQ's  |  Contact  |  Terms of Service  |  Article Submission Guidelines  |  Writers' Contests  |  Privacy  |  Mission / About
Copyright © 1999-2009 SearchWarp.com, All Rights Reserved - SearchWarp.com is an IcoLogic, Inc. Company