- Community Home
- >
- Networking
- >
- Switching and Routing
- >
- HPE Aruba Networking & ProVision-based
- >
- Combining edge port isolation and core DHCP snoopi...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-27-2015 05:32 AM
02-27-2015 05:32 AM
Combining edge port isolation and core DHCP snooping
HEllo, In a Students boarding School with shared wired network, i'm facing many DHCP rogue problems. Because they want to extend LAN with their own wifi router (badly configured of course).
For easy mangement they are in the same subnet.
The porpose of network is for Internet access only (DHCP+proxy+firewall+content filter)
edge switches are 2510-48, they are all connected to a core switch 2810-24G.
first I tried port isolation on 2510 with protected-ports. This is better but seems there still are DHCP problems. I think that rogue Dhcp traffic go thru uplinks.
My question is, if I replace 2810 core with newer DHCP snooping compatible switch, will it be enough ?
Another idea would be to have 1 different VLAN per switch with different subnets, so no need to change core switch, but some more routing difficulties.
Thank for suggestions.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-03-2015 10:57 AM
03-03-2015 10:57 AM
Re: Combining edge port isolation and core DHCP snooping
Hello,
Back with maybe a simplier solution :
I've added filter source-port to prevent traffic beteween uplinks on the core 2810 switch.
This is a feature available on 2810 switch.
Maybe I'll do VLAN solution later for better management.