Cisco CCNA (200-301)Security FundamentalsMedium

A network engineer enables DHCP snooping on a switch. Clients on access ports stop receiving IP addresses from the legitimate DHCP server connected via the uplink trunk port. What is the most likely cause?

  1. AThe DHCP server's MAC address was not added to port security
  2. BDHCP snooping requires DAI to be enabled first
  3. CThe uplink port was not configured as a trusted DHCP snooping port
  4. DThe access ports need a wildcard mask configured for DHCP relay
Show answer & explanation

Correct answer: C. The uplink port was not configured as a trusted DHCP snooping port

By default, all ports are untrusted when DHCP snooping is enabled, so DHCP server reply messages (OFFER/ACK) arriving on the uplink are dropped unless that port is explicitly marked trusted with 'ip dhcp snooping trust'.

Why the other options are wrong

  • A. Port security MAC limits are unrelated to DHCP message filtering.
  • B. DAI is a separate feature and not a prerequisite for DHCP snooping.
  • D. Wildcard masks apply to ACLs/routing, not DHCP relay configuration.

DHCP Snooping Trust

DHCP snooping filters DHCP messages based on trusted/untrusted port status to prevent rogue DHCP servers.

  • All ports untrusted by default when feature enabled
  • Uplink toward legitimate DHCP server must be trusted
  • Untrusted ports block DHCP server replies (OFFER, ACK)

Memory trick: Trust the Tower (uplink), Suspect the Street (access ports)

More Security Fundamentals questions