<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: dhcp-snooping trusted servers in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16566#M379</link>
    <description>The problem is that if we specify trusted servers, we can have only a maximum of 8 server addresses across the whole switch.  If we have two addresses used for the server's real addresses, then we need one for the dhcp helper in each vlan, meaning we need to configure three addresses in each VLAN so enabling this on two vlans will use up three of the 8 available entries and so no more vlans can have dhcp snooping enabled (with trusted server addresses).  This seems a remarkably low limit.&lt;BR /&gt;</description>
    <pubDate>Mon, 16 Jan 2017 19:03:00 GMT</pubDate>
    <dc:creator>David_Rickard</dc:creator>
    <dc:date>2017-01-16T19:03:00Z</dc:date>
    <item>
      <title>dhcp-snooping trusted servers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16558#M371</link>
      <description>Hi all,&lt;BR /&gt;
&lt;BR /&gt;
I am just looking at using extreme as edge switches, have been using them for core and aggregation for years.  We have a large network with two central DHCP servers which we then use UDP forwarding from each user vlan.&lt;BR /&gt;
&lt;BR /&gt;
As I see it, we need to enable dhcp snooping on all ports of the switch including the uplinks so they see the server packets on the uplinks as well as the client packets on the edge ports.  This will discard server packets on all ports by default so we either need to set the uplinks as trusted ports or use the trusted server feature.&lt;BR /&gt;
&lt;BR /&gt;
The trusted server commend is better because it will guard against rogue packets on the uplinks too, but there is a limit of 8 and if we have four user vlans on a switch, we would need to issue two trusted server commands for each of the central servers on each vlan (eight commands) PLUS one per VLAN for the local gateway relay address so we will easily run out of trusted servers.&lt;BR /&gt;
&lt;BR /&gt;
Is this right? How do people get round this, or do you just use the trusted port commands for large networks?&lt;BR /&gt;
&lt;BR /&gt;
Also, I have read somewhere you can't put snooping on LAG ports, as all our uplinks are LAGged does this mean the feature is completely useless to us anyway?&lt;BR /&gt;</description>
      <pubDate>Mon, 11 Jul 2016 16:02:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16558#M371</guid>
      <dc:creator>David_Rickard</dc:creator>
      <dc:date>2016-07-11T16:02:00Z</dc:date>
    </item>
    <item>
      <title>RE: dhcp-snooping trusted servers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16559#M372</link>
      <description>David, &lt;BR /&gt;
&lt;BR /&gt;
Have you checked the bootprelay command?&lt;BR /&gt;
&lt;BR /&gt;
You can enable it globally for a virtual router and all its vlans&lt;BR /&gt;
enable bootprelay vr vr-defaultor only for specific vlans &lt;BR /&gt;
enable bootprelay vlan test&lt;BR /&gt;
You can also add one or more DHCP servers globally to the virtual router for all vlans to use&lt;BR /&gt;
configure bootprelay add 10.1.0.1or configure specific DHCP servers for individual vlans&lt;BR /&gt;
configure bootprelay vlan test add 10.2.0.2&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 11 Jul 2016 22:53:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16559#M372</guid>
      <dc:creator>dflouret</dc:creator>
      <dc:date>2016-07-11T22:53:00Z</dc:date>
    </item>
    <item>
      <title>RE: dhcp-snooping trusted servers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16560#M373</link>
      <description>Why?  We have udp forwarding working well, has been for years on many switches.  My question is about dhcp-snooping,&lt;BR /&gt;</description>
      <pubDate>Tue, 12 Jul 2016 11:36:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16560#M373</guid>
      <dc:creator>David_Rickard</dc:creator>
      <dc:date>2016-07-12T11:36:00Z</dc:date>
    </item>
    <item>
      <title>RE: dhcp-snooping trusted servers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16561#M374</link>
      <description>I'm sorry, I misread your question.&lt;BR /&gt;</description>
      <pubDate>Tue, 12 Jul 2016 12:16:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16561#M374</guid>
      <dc:creator>dflouret</dc:creator>
      <dc:date>2016-07-12T12:16:00Z</dc:date>
    </item>
    <item>
      <title>RE: dhcp-snooping trusted servers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16562#M375</link>
      <description>No problem Daniel, if you have any advice regarding the snooping I'd be really grateful, this seems very confusing.&lt;BR /&gt;</description>
      <pubDate>Tue, 12 Jul 2016 12:55:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16562#M375</guid>
      <dc:creator>David_Rickard</dc:creator>
      <dc:date>2016-07-12T12:55:00Z</dc:date>
    </item>
    <item>
      <title>RE: dhcp-snooping trusted servers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16563#M376</link>
      <description>David, &lt;BR /&gt;
&lt;BR /&gt;
How many DHCP Servers do you have ?</description>
      <pubDate>Wed, 13 Jul 2016 01:54:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16563#M376</guid>
      <dc:creator>Balaji</dc:creator>
      <dc:date>2016-07-13T01:54:00Z</dc:date>
    </item>
    <item>
      <title>RE: dhcp-snooping trusted servers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16564#M377</link>
      <description>We have a large network with two central DHCP servers which we then use UDP forwarding from each user vlan.  The problem is that we have seen once DHCP clients have had a response to the initial broadcast, they seem to unicast directly to the server IP, so our current snooping settings (on HP switches) has to recognise the local relay agent and the central servers.  That's fine but when the settings are tied to a VLAN, that means three trusted servers have to be enabled per vlan and with a limit of 8 across the whole switch, that means we can't have more than two vlans with DHCP.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Wed, 13 Jul 2016 13:47:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16564#M377</guid>
      <dc:creator>David_Rickard</dc:creator>
      <dc:date>2016-07-13T13:47:00Z</dc:date>
    </item>
    <item>
      <title>RE: dhcp-snooping trusted servers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16565#M378</link>
      <description>I can see so far nothing has been updated here for  the last 6 months or so. &lt;BR /&gt;
&lt;BR /&gt;
Coming to the dhcp-snooping for trusted servers what i could suggest you as below:&lt;BR /&gt;
&lt;BR /&gt;
You can enable DHCP snooping on a per port and per vlan basis but coming to trusted DHCP server it is always on a per vlan basis only.  If configured for DHCP snooping, the switch snoops DHCP packets on the indicated ports and builds a DHCP bindings database of IP address and MAC address bindings from the received packets.&lt;BR /&gt;
&lt;BR /&gt;
If configured for trusted DHCP server, the switch forwards only DHCP packets from the trusted&lt;BR /&gt;
servers. The switch drops DHCP packets from other DHCP snooping-enabled ports.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 16 Jan 2017 14:36:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16565#M378</guid>
      <dc:creator>Tripathy__Priya</dc:creator>
      <dc:date>2017-01-16T14:36:00Z</dc:date>
    </item>
    <item>
      <title>RE: dhcp-snooping trusted servers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16566#M379</link>
      <description>The problem is that if we specify trusted servers, we can have only a maximum of 8 server addresses across the whole switch.  If we have two addresses used for the server's real addresses, then we need one for the dhcp helper in each vlan, meaning we need to configure three addresses in each VLAN so enabling this on two vlans will use up three of the 8 available entries and so no more vlans can have dhcp snooping enabled (with trusted server addresses).  This seems a remarkably low limit.&lt;BR /&gt;</description>
      <pubDate>Mon, 16 Jan 2017 19:03:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16566#M379</guid>
      <dc:creator>David_Rickard</dc:creator>
      <dc:date>2017-01-16T19:03:00Z</dc:date>
    </item>
    <item>
      <title>RE: dhcp-snooping trusted servers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16567#M380</link>
      <description>Hi David, &lt;BR /&gt;
let's assume that your uplink ports on edge switch are trusted.&lt;BR /&gt;
&lt;BR /&gt;
Add trusted port without DHCP servers&lt;BR /&gt;
&lt;BR /&gt;
configure trusted-ports 50 trust-for dhcp-server&lt;BR /&gt;
From EXOS command reference:&lt;BR /&gt;
Trusted ports do not block traffic; rather, the switch forwards any DHCP server packets that appear on trusted ports.&lt;BR /&gt;
You can also add on your uplink port:&lt;BR /&gt;
&lt;BR /&gt;
enable ip-security dhcp-snooping vlan lan1 port 50 violation-action none&lt;BR /&gt;
enable ip-security dhcp-snooping vlan lan2 port 50 violation-action none&lt;BR /&gt;
enable ip-security dhcp-snooping vlan lan3 port 50 violation-action none--&lt;BR /&gt;
Jarek</description>
      <pubDate>Mon, 16 Jan 2017 19:03:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16567#M380</guid>
      <dc:creator>Jarek</dc:creator>
      <dc:date>2017-01-16T19:03:00Z</dc:date>
    </item>
    <item>
      <title>RE: dhcp-snooping trusted servers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16568#M381</link>
      <description>Adding to  this what Jarek mentioned depending upon DHCP snooping configuration the switch drops packets and can disable the port either temporarily or permanently, even can black hole the MAC address too. Configuring one or more trusted ports the switch assumes that all DHCP server packets on the trusted port are valid.&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 17 Jan 2017 13:28:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16568#M381</guid>
      <dc:creator>Tripathy__Priya</dc:creator>
      <dc:date>2017-01-17T13:28:00Z</dc:date>
    </item>
    <item>
      <title>RE: dhcp-snooping trusted servers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16569#M382</link>
      <description>I know what dhcp snooping does, if you read my posts you will see I get all that.  I was not asking  what dhcp snooping does or how to configure it.  I did not ask how to trust a port, or what trusting ports does.&lt;BR /&gt;
&lt;BR /&gt;
For thr fourth time in this thread I will explain the question.&lt;BR /&gt;
&lt;BR /&gt;
There is a restriction of no more than 8 trusted servers on a switch.&lt;BR /&gt;
&lt;BR /&gt;
If you have two DHCP servers, they have a native address each , that is two.&lt;BR /&gt;
If they are routed, you then have one address for the DHCP helper, that makes three.&lt;BR /&gt;
&lt;BR /&gt;
You have to configure the trusted servers per vlan, so you have to specify three addresses for each VLAN.&lt;BR /&gt;
&lt;BR /&gt;
Doing this for two VLANS uses six addresses out of the 8 you can use.&lt;BR /&gt;
&lt;BR /&gt;
This means if you use DHCP snooping trusted servers, you can't do it for more than two VLANs.  This seems like an unreasonable restriction.  I was asking whether that is correct, or whether I have misunderstood how that works.&lt;BR /&gt;</description>
      <pubDate>Tue, 17 Jan 2017 14:46:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16569#M382</guid>
      <dc:creator>David_Rickard</dc:creator>
      <dc:date>2017-01-17T14:46:00Z</dc:date>
    </item>
    <item>
      <title>RE: dhcp-snooping trusted servers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16570#M383</link>
      <description>David, &lt;BR /&gt;
you asked also "How do people get round this, or do you just use the trusted port commands for large networks?"&lt;BR /&gt;
&lt;BR /&gt;
Short example  how I use DHCP and  ip-sec features:&lt;BR /&gt;
1) Edge (L2) only uplink port is trusted for dhcp servers&lt;BR /&gt;
- I don't use trusted servers per vlan, because we trust our network&lt;BR /&gt;
- dhcp-snooping  with violation-action drop-packet block-mac duration&lt;BR /&gt;
- If hardware has space for ACL: ip-security source-ip-lockdown&lt;BR /&gt;
&lt;BR /&gt;
2) Aggregation (L2/L3) &lt;BR /&gt;
- bootprelay with two DHCP servers &lt;BR /&gt;
- dhcp-snooping with  violation-action drop-packet block-mac duration &lt;BR /&gt;
- two DHCP trusted servers on uplink vlan to core&lt;BR /&gt;
- arp validation &lt;BR /&gt;
- enable arp learning learn-from-dhcp, disable arp learning learn-from-arp&lt;BR /&gt;
- arp gratuitous-protection&lt;BR /&gt;
- ip-security dhcp-bindings storage&lt;BR /&gt;
- ACL filters per vlan&lt;BR /&gt;
&lt;BR /&gt;
--&lt;BR /&gt;
Jarek</description>
      <pubDate>Tue, 17 Jan 2017 14:46:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16570#M383</guid>
      <dc:creator>Jarek</dc:creator>
      <dc:date>2017-01-17T14:46:00Z</dc:date>
    </item>
    <item>
      <title>RE: dhcp-snooping trusted servers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16571#M384</link>
      <description>Thanks, we have been using trusted ports because our HP switches don't do it per VLAN, so it's less restrictive and we were just expecting to do the same with extreme.  As for why, we don't trust our network being a large university all sorts of stuff gets plugged into our switches without us knowing! So the trusted port is better than nothing but doesn't cover all the bases.&lt;BR /&gt;
&lt;BR /&gt;
It's interesting using DHCP on your aggregation, we don't becuase we do trust our core, but maybe we shouldn't.  That's really helpful thanks.&lt;BR /&gt;</description>
      <pubDate>Tue, 17 Jan 2017 14:46:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16571#M384</guid>
      <dc:creator>David_Rickard</dc:creator>
      <dc:date>2017-01-17T14:46:00Z</dc:date>
    </item>
    <item>
      <title>RE: dhcp-snooping trusted servers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16572#M385</link>
      <description>David, my explanation was to short .&lt;BR /&gt;
&lt;BR /&gt;
"Aggregation - bootprelay with two DHCP servers "&lt;BR /&gt;
&lt;BR /&gt;
I meant, I have 2 central DHCP servers, and I use bootprelay on agggregation switches. &lt;BR /&gt;
&lt;BR /&gt;
About "two DHCP trusted servers on uplink vlan to core"&lt;BR /&gt;
&lt;BR /&gt;
I have L3 connection only between core and aggragation.&lt;BR /&gt;
Because I use dhcp-snooping, I need a trusted port with ip-security  violation-action none (for dhcp-snooping table), and so on ..&lt;BR /&gt;
&lt;BR /&gt;
--&lt;BR /&gt;
Jarek</description>
      <pubDate>Tue, 17 Jan 2017 14:46:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16572#M385</guid>
      <dc:creator>Jarek</dc:creator>
      <dc:date>2017-01-17T14:46:00Z</dc:date>
    </item>
    <item>
      <title>RE: dhcp-snooping trusted servers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16573#M386</link>
      <description>Your DHCP configuration is the same as ours, but we don't presently do DHCP snooping on the L3 connection to the core&lt;BR /&gt;
&lt;BR /&gt;
I have just re-read my post and I made that very confusing.  We do trusted servers on our HP switches as it is not vlan-tied so it's easy to configure, but by having to put all the trusted servers in each vlan, extremes then run into the restriction.&lt;BR /&gt;
&lt;BR /&gt;
I guess I have my answer in that everyone just uses trsted ports but with your additional measure of trusted servers on the L3 link.&lt;BR /&gt;
&lt;BR /&gt;
Many thanks&lt;BR /&gt;</description>
      <pubDate>Tue, 17 Jan 2017 14:46:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-trusted-servers/m-p/16573#M386</guid>
      <dc:creator>David_Rickard</dc:creator>
      <dc:date>2017-01-17T14:46:00Z</dc:date>
    </item>
  </channel>
</rss>

