Cisco CCNA (200-301)Security FundamentalsMedium
A network engineer enables DHCP snooping on a switch. Clients on access ports stop receiving IP addresses from the legitimate DHCP server connected via the uplink trunk port. What is the most likely cause?
- AThe DHCP server's MAC address was not added to port security
- BDHCP snooping requires DAI to be enabled first
- CThe uplink port was not configured as a trusted DHCP snooping port
- DThe access ports need a wildcard mask configured for DHCP relay
Show answer & explanationAnswer & explanation
Correct answer: C. The uplink port was not configured as a trusted DHCP snooping port
By default, all ports are untrusted when DHCP snooping is enabled, so DHCP server reply messages (OFFER/ACK) arriving on the uplink are dropped unless that port is explicitly marked trusted with 'ip dhcp snooping trust'.
Why the other options are wrong
- A. Port security MAC limits are unrelated to DHCP message filtering.
- B. DAI is a separate feature and not a prerequisite for DHCP snooping.
- D. Wildcard masks apply to ACLs/routing, not DHCP relay configuration.
DHCP Snooping Trust
DHCP snooping filters DHCP messages based on trusted/untrusted port status to prevent rogue DHCP servers.
- All ports untrusted by default when feature enabled
- Uplink toward legitimate DHCP server must be trusted
- Untrusted ports block DHCP server replies (OFFER, ACK)
Memory trick: Trust the Tower (uplink), Suspect the Street (access ports)