Switching

last person joined: 16 hours ago 

Ask questions and share experiences about EX and QFX portfolios and all switching solutions across your data center, campus, and branch locations.
  • 1.  Configuring DHCP Snooping and DAI on EX Switches

    Posted 06-08-2014 21:04

    hi guys,

     

         in my network environment now we have a pair of EX 4500 running on VC (Core Switch) and EX 4200 running on VC as well (2 stacks as edge switch) , connected and interfacing with EX 4500.

     

         what i want to do now is to configure DHCP Snooping and DAI (dynamic ARP inspection) to prevent man-in the middle attacks.

     

         Do i have to configure DHCP snooping and DAI on both the EX 4500 and 4200s? i assume i will need to set examine dhcp and arp inspection for all of my 20 vlans?

     

        



  • 2.  RE: Configuring DHCP Snooping and DAI on EX Switches

     
    Posted 06-10-2014 00:50

    You need to configure security features only on the edge switch(where the potential attackers are connected).

     

     

     

    =====

    If this worked for you please flag my post as an "Accepted Solution" so others can benefit. A kudo would be cool if you think I earned it.



  • 3.  RE: Configuring DHCP Snooping and DAI on EX Switches

    Posted 06-10-2014 01:57

    Hi Reggaez,

     

    As per your scenario you should configure the DHCP-snooping & DAI  on EX-4200 switches(edge-switches).

     

    and the command for configuring the DHCP-snooping & DAI  is,

     

    #set ethernet-switching-options secure-access-port vlan <vlan-name> arp-inspection

    #set ethernet-switching-options secure-access-port vlan <vlan-name> examine-dhcp

     

     



  • 4.  RE: Configuring DHCP Snooping and DAI on EX Switches

    Posted 06-22-2014 03:14

    Hi suresh,

     

         thanks for the info. now i have another question,  the DHCP server is running on a Hyper-V server and is connected to a Server Farm switch (CISCO 3750) , in this scenario, where do i set the trusted port for the DHCP snooping?

     

        right now the setup is 

     

     EX 4200 (Access Switches) ---> EX 4500 (Core) ---> Cisco 3750 (Server Farm) ----> DHCP Server.

     

        do i set the trusted port at Cisco 3750? or i still need to set the trusted port at the core switch as well?



  • 5.  RE: Configuring DHCP Snooping and DAI on EX Switches
    Best Answer

    Posted 06-24-2014 23:18

    The trunk ports connecting the access to the core and core to CISCO are DHCP trusted already.