Switches, Hubs, and Modems
1753261 Members
4977 Online
108792 Solutions
New Discussion юеВ

Restrict DHCP servers?

 
SOLVED
Go to solution
Claes A
New Member

Restrict DHCP servers?

Howdy,

I work at a school with a simple VLAN-setup... Vlan 1: students
Vlan 2: teachers
Vlan 3: servers

Among other things a DHCP serevr is set up on the server vlan and on my procurve 5308 I have configured the IP-helper parameter to relay DHCP-requests to and from clients... all good.
However every now and then some creative student decides to start up a DHCP-server of his/her own... and of course since theirs no routing pathes to that DCP-server it answers any client requests first...

So my question is: Is there any function in the 5308 to specify allowed DHCP servers and drop any DHCP answers from servers not in the "allowed list"?
Or does anyone have another solution to this problem?

thanks alot!
5 REPLIES 5
Matt Hobbs
Honored Contributor
Solution

Re: Restrict DHCP servers?

There is a new DHCP snooping feature available on most ProCurve switches. Check the firmware release notes for more information on this.

ftp://ftp.hp.com/pub/networking/software/5300xl-RelNotes-e1061-59912127.pdf
Claes A
New Member

Re: Restrict DHCP servers?

Perfect... that should do it.. thanks for the help!
RobB_8
Advisor

Re: Restrict DHCP servers?

interesting idea...
does anyone know if HP put together a nice little reference table of what models and min firmware support dhcp-snooping? Kind of like the Customer Advisory's they sent out on the CDP and non HP GBIC's.
Claes A
New Member

Re: Restrict DHCP servers?

I tried the DHCP snooping thingie and it works fine and meets my needs... as long as we're talking windows environment...
We use CD's with an old fashioned DOS-boot that starts up the computer on the network, connects to a share and installs an ghost-image. And for some reason the DOS-DHCP-Client does not receive an IP-address as long as dhcp snooping is enabled on the switch (same computer in the same switch port works great when running windows).
RobB_8
Advisor

Re: Restrict DHCP servers?

Most imaging software (CD or PXE boot) uses BootP to get an IP from a DHCP server not DHCP from a DHCP server. I would assume that dhcp-snooping is not capable of managing bootp packets.