<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: DHCP-Snooping, ARP validation with port specific tags. in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-arp-validation-with-port-specific-tags/m-p/47556#M12257</link>
    <description>I am not allowed to run the command &lt;BR /&gt;
&lt;BR /&gt;
configure vlan Test add ports 16 tagged 10..  because  the options are &lt;BR /&gt;
 &lt;CR&gt;            Execute the command  stpd            STP domain&lt;BR /&gt;
  &lt;STPD_NAME&gt;     STP domain name&lt;BR /&gt;
    "s0"&lt;BR /&gt;
&lt;BR /&gt;
so from what I am seeing 3 different STP domains &lt;BR /&gt;
Default (cr) &lt;BR /&gt;
10 &lt;BR /&gt;
11&lt;BR /&gt;
&lt;BR /&gt;
I would use the same config from the real life scenario on the test switch and retest&lt;BR /&gt;
Jason&lt;BR /&gt;
&lt;BR /&gt;&lt;/STPD_NAME&gt;&lt;/CR&gt;</description>
    <pubDate>Mon, 07 Nov 2016 23:21:00 GMT</pubDate>
    <dc:creator>Jason_Parker</dc:creator>
    <dc:date>2016-11-07T23:21:00Z</dc:date>
    <item>
      <title>DHCP-Snooping, ARP validation with port specific tags.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-arp-validation-with-port-specific-tags/m-p/47555#M12256</link>
      <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
I have a case where i can't get DHCP-Snooping with ARP validation&lt;BR /&gt;
working when using port specific tags.&lt;BR /&gt;
&lt;BR /&gt;
In my homelab i've used the following settings (which work):&lt;BR /&gt;
- DHCP server on port 6.&lt;BR /&gt;
- Client on port 10.&lt;BR /&gt;
* config lines:&lt;BR /&gt;
configure trusted-port 6 trust-for dhcp-server&lt;BR /&gt;
enable ip-security dhcp-snooping "Default" ports 6,10 violation-action drop-packet&lt;BR /&gt;
enable ip-security arp validation vlan "Default" ports 10 violation-action drop-packet&lt;BR /&gt;
&lt;BR /&gt;
In my real life scenario things are a little different (this doens't work):&lt;BR /&gt;
- DHCP server behind a different switch (uplinked to port 15).&lt;BR /&gt;
- Multiple vlans behind port 16 (port specific tag).&lt;BR /&gt;
* config lines:&lt;BR /&gt;
create vlan "Test"&lt;BR /&gt;
configure vlan Test tag 9&lt;BR /&gt;
disable igmp snooping vlan "Test"&lt;BR /&gt;
configure vlan Test add ports 15 tagged&lt;BR /&gt;
configure vlan Test add ports 16 tagged 10&lt;BR /&gt;
configure vlan Test add ports 16 tagged 11&lt;BR /&gt;
configure trusted-port 15 trust-for dhcp-server&lt;BR /&gt;
enable ip-security dhcp-snooping "Test" ports 15,16 violation-action drop-packet&lt;BR /&gt;
enable ip-security arp validation vlan "Test" ports 16 violation-action drop-packet&lt;BR /&gt;
&lt;BR /&gt;
#&lt;BR /&gt;
command "enable ip-security dhcp-snooping "Test" ports 15,16 violation-action drop-packet" gives an error: ERROR: Port 16 does not belong to vlan Test.&lt;BR /&gt;
&lt;BR /&gt;
command" enable ip-security arp validation vlan "Test" ports 16 violation-action drop-packet"&lt;BR /&gt;
does not give an error but just doesn't seem to do anything&lt;BR /&gt;
&lt;BR /&gt;
Does anybody know if this is possible while using port specific tags?&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 07 Nov 2016 22:46:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-arp-validation-with-port-specific-tags/m-p/47555#M12256</guid>
      <dc:creator>dilu</dc:creator>
      <dc:date>2016-11-07T22:46:00Z</dc:date>
    </item>
    <item>
      <title>RE: DHCP-Snooping, ARP validation with port specific tags.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-arp-validation-with-port-specific-tags/m-p/47556#M12257</link>
      <description>I am not allowed to run the command &lt;BR /&gt;
&lt;BR /&gt;
configure vlan Test add ports 16 tagged 10..  because  the options are &lt;BR /&gt;
 &lt;CR&gt;            Execute the command  stpd            STP domain&lt;BR /&gt;
  &lt;STPD_NAME&gt;     STP domain name&lt;BR /&gt;
    "s0"&lt;BR /&gt;
&lt;BR /&gt;
so from what I am seeing 3 different STP domains &lt;BR /&gt;
Default (cr) &lt;BR /&gt;
10 &lt;BR /&gt;
11&lt;BR /&gt;
&lt;BR /&gt;
I would use the same config from the real life scenario on the test switch and retest&lt;BR /&gt;
Jason&lt;BR /&gt;
&lt;BR /&gt;&lt;/STPD_NAME&gt;&lt;/CR&gt;</description>
      <pubDate>Mon, 07 Nov 2016 23:21:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-arp-validation-with-port-specific-tags/m-p/47556#M12257</guid>
      <dc:creator>Jason_Parker</dc:creator>
      <dc:date>2016-11-07T23:21:00Z</dc:date>
    </item>
    <item>
      <title>RE: DHCP-Snooping, ARP validation with port specific tags.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-arp-validation-with-port-specific-tags/m-p/47557#M12258</link>
      <description>I don't understand you.&lt;BR /&gt;
&lt;BR /&gt;
I can run command "configure vlan Test add ports 16 tagged 10" fine that is not the problem. (it also works as expected).&lt;BR /&gt;
&lt;BR /&gt;
"configure trusted-port 15 trust-for dhcp-server" also isn't a problem.&lt;BR /&gt;
&lt;BR /&gt;
I have problems with these two:&lt;BR /&gt;
1: enable ip-security dhcp-snooping "Test" ports 15,16 violation-action drop-packet&lt;BR /&gt;
2: enable ip-security arp validation vlan "Test" ports 16 violation-action drop-packet&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 07 Nov 2016 23:21:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-arp-validation-with-port-specific-tags/m-p/47557#M12258</guid>
      <dc:creator>dilu</dc:creator>
      <dc:date>2016-11-07T23:21:00Z</dc:date>
    </item>
    <item>
      <title>RE: DHCP-Snooping, ARP validation with port specific tags.</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-arp-validation-with-port-specific-tags/m-p/47558#M12259</link>
      <description>Port-Specific VLAN Tag is supported on the following platforms:  • Summit X460-G2 (supported from ExtremeXOS 15.6)  • Summit X670-G2 (supported from ExtremeXOS 15.6)  • Summit X770    May be this command is not available in versions lower than 15.6 EXOS .    Dilu could you share the "show switch" output so that i can check this in background and get back to you on the below error?    ERROR: Port 16 does not belong to vlan Test.</description>
      <pubDate>Wed, 30 Nov 2016 10:51:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-arp-validation-with-port-specific-tags/m-p/47558#M12259</guid>
      <dc:creator>Karthik_Mohando</dc:creator>
      <dc:date>2016-11-30T10:51:00Z</dc:date>
    </item>
  </channel>
</rss>

