9.1 DHCP Snooping and Dynamic ARP Inspection
Key Takeaways
DHCP Snooping acts as a Layer 2 perimeter firewall, classifying switch ports into trusted (uplinks to authorized DHCP servers) and untrusted (access ports where server responses are discarded).
The DHCP Snooping Binding Table dynamically tracks authenticated client MAC-to-IP bindings, lease times, VLANs, and switch ports, providing the foundational telemetry for downstream security features.
Dynamic ARP Inspection (DAI) uses the DHCP snooping database to validate Address Resolution Protocol packets on untrusted ports, thwarting ARP cache poisoning and Man-in-the-Middle (MitM) attacks.
Uplinks connecting access switches to default gateways or core infrastructure must be explicitly designated as trusted for both DHCP Snooping and DAI to prevent legitimate network traffic from being dropped.
In AOS-CX 10.14, enable DHCP snooping globally with
dhcp-snoopingand per VLAN withdhcp-snoopingin VLAN context, enable ARP inspection witharp inspectionin VLAN context, and trust uplinks withdhcp-snooping trustandarp inspection trust(older releases useddhcpv4-snooping).
DHCP Snooping and Dynamic ARP Inspection
Quick Summary: Standard Ethernet networks operate on an implicit trust model where any connected endpoint can broadcast network control messages. Attackers exploit this design by introducing rogue DHCP servers or broadcasting fraudulent Address Resolution Protocol (ARP) responses to execute Man-in-the-Middle (MitM) and Denial-of-Service (DoS) attacks. DHCP Snooping mitigates rogue DHCP servers by categorizing switch ports into trusted and untrusted interfaces and dynamically building a secure binding database. Dynamic ARP Inspection (DAI) leverages this binding table to intercept and validate ARP packets on untrusted ports, ensuring that Layer 2 MAC addresses match authorized Layer 3 IP assignments.
The Layer 2 Threat Landscape: Rogue DHCP and ARP Spoofing
Within a standard broadcast domain, client devices broadcast requests to discover network infrastructure services. Because Layer 2 switches forward broadcast frames out all active ports within a VLAN by default, any host can listen to or respond to these discovery broadcasts.
The Threat of Rogue DHCP Servers
When an endpoint joins an Ethernet network, it broadcasts a DHCP Discover message. Any DHCP server residing in that broadcast domain can respond with a DHCP Offer. A rogue DHCP server—whether placed intentionally by an attacker or accidentally by an employee connecting an unmanaged wireless router—introduces severe security vulnerabilities:
- Man-in-the-Middle (MitM) Traffic Redirection: The rogue server responds faster than the legitimate enterprise DHCP server, supplying client devices with a fraudulent default gateway address (pointing to the attacker's workstation). All outbound client traffic is intercepted, analyzed, or altered before being forwarded upstream.
- DNS Hijacking: The rogue server assigns the IP address of an attacker-controlled DNS server, redirecting users to phishing portals or credential-harvesting clones of corporate services.
- Denial of Service (DoS): The rogue server leases invalid IP configurations (such as an incorrect subnet mask or unroutable gateway), completely severing client connectivity.
- DHCP Starvation Attacks: An attacker uses automated tools (such as Yersinia) to flood the legitimate DHCP server with thousands of DHCP Discover messages containing randomized MAC addresses. This exhausts the available IP scope, preventing legitimate enterprise devices from acquiring network access.
ARP Protocol Vulnerabilities and Cache Poisoning
The Address Resolution Protocol (ARP, RFC 826) maps known Layer 3 IPv4 addresses to dynamic Layer 2 Ethernet MAC addresses. However, ARP possesses no built-in authentication mechanisms:
- Stateless and Unverified: Devices process and cache ARP replies even if they never transmitted a corresponding ARP request.
- Gratuitous ARP Poisoning: An attacker can transmit an unsolicited Gratuitous ARP (GARP) frame asserting that the default gateway's IP address is now associated with the attacker's own MAC address. The victim workstation and the default gateway both update their local ARP caches with this forged binding.
- Traffic Interception: Outbound packets from the victim to external networks are delivered directly to the attacker's switch port at Layer 2. The attacker enables IP forwarding to relay packets to the real gateway, eavesdropping on unencrypted traffic without the victim detecting connection disruption.
DHCP Snooping Operational Mechanics
DHCP Snooping acts as a Layer 2 perimeter firewall on the access switch, inspecting DHCP control messages exchanged between clients and servers. It operates by enforcing a strict classification of physical switch ports:
+---------------------------------------------------------------------------------------------------------+
| DHCP SNOOPING PORT ARCHITECTURE |
| |
| [ Untrusted Port 1/1/1 ] --------> Client Workstation (Permits DHCP Discover / Request) |
| (DISCARDS Rogue DHCP Offer / ACK / NAK Frames!) |
| |
| [ AOS-CX Access Switch ] --------> Maintains DHCP Snooping Binding Table in Hardware |
| [ MAC | IP | Lease | Type | VLAN | Port ] |
| |
| [ Trusted Port 1/1/48 ] ---------> Uplink to Enterprise DHCP Server / Core Router |
| (Permits all DHCP messages: Discover, Offer, Request, ACK) |
+---------------------------------------------------------------------------------------------------------+
Trusted vs. Untrusted Ports
-
Untrusted Ports:
- By default, once DHCP Snooping is enabled on a VLAN, all switch ports in that VLAN operate in untrusted mode.
- Untrusted ports connect to edge endpoints: user laptops, desktop workstations, printers, and standard IoT devices.
- Allowed Ingress Traffic: Client-originated DHCP messages, including
DHCPDISCOVER,DHCPREQUEST,DHCPDECLINE, andDHCPRELEASE. - Blocked Ingress Traffic: Server-originated DHCP messages, including
DHCPOFFER,DHCPACK, andDHCPNAK. If an untrusted port receives a server-generated frame, the switch immediately discards the frame, increments a security violation counter, and generates an administrative log.
-
Trusted Ports:
- Network engineers must explicitly configure uplinks connecting to legitimate enterprise DHCP servers, DHCP relay agents, or upstream aggregation/core switches as trusted.
- Allowed Ingress Traffic: All DHCP messages (both client requests and server responses) flow unimpeded without filtering.
The DHCP Snooping Binding Database
As legitimate endpoints complete the four-step DHCP transaction (DORA: Discover, Offer, Request, ACK) across untrusted ports and trusted uplinks, the access switch snoops the passing frames. Upon observing a valid DHCPACK returning from a trusted port, the switch dynamically records an entry in the DHCP Snooping Binding Table:
| Attribute | Description | Example Entry |
|---|---|---|
| MAC Address | Hardware Layer 2 address of the client NIC | 00:50:56:fd:aa:12 |
| IP Address | Leased Layer 3 IPv4 address assigned by server | 10.10.20.105 |
| Lease Time | Duration of the lease in seconds | 86400 seconds (24 hours) |
| Binding Type | Origin of the binding (dynamic or static) | dynamic |
| VLAN ID | Layer 2 broadcast domain of the access port | VLAN 20 |
| Interface | Physical switch port where the client resides | 1/1/1 |
The switch maintains this table dynamically: when a client gracefully disconnects via DHCPRELEASE or the lease timer expires, the corresponding binding is removed. If a device uses a static IP address, an administrator can manually configure a static binding entry.
DHCP Option 82 Support
DHCP Snooping also supports DHCP Option 82 (Relay Agent Information Option). When an access switch intercepts a DHCP Discover on an untrusted port, it can append sub-options identifying the client's physical switch chassis, module, and port (Circuit ID) and switch identifier (Remote ID). The upstream DHCP server uses this metadata to allocate specific IP subnets or lease policies based on physical switch port locations.
Dynamic ARP Inspection (DAI) Mechanics
While DHCP Snooping protects the initial address acquisition process, Dynamic ARP Inspection (DAI)—referred to as ARP Protection in some AOS-S documentation and ARP Inspection in AOS-CX—secures ongoing Layer 2 to Layer 3 address resolution.
Validation Process on Untrusted Ports
DAI intercepts all ARP Request and ARP Reply frames arriving on untrusted switch ports. Before forwarding an ARP packet, the switch hardware compares the sender information stored inside the ARP packet payload against the verified DHCP Snooping Binding Table:
- Payload Inspection: The switch extracts the Sender Hardware Address (SHA) and Sender Protocol Address (SPA) from the ARP payload.
- Binding Table Lookup: The switch queries its internal database to verify if an active entry exists linking that exact MAC address (SHA) to that exact IP address (SPA) on that specific ingress interface and VLAN.
- Forwarding Decision:
- Valid Match: The ARP frame is forwarded out normal switch ports.
- Invalid or Missing Entry: If the IP-MAC pairing does not match an active lease, or if no entry exists for that host, the frame is dropped immediately, and a security violation is logged.
Trusted Ports in DAI
Just as with DHCP Snooping, interfaces connecting to upstream default gateways, core switches, and trusted servers are configured as ARP Inspection Trusted. ARP packets received on trusted ports bypass inspection entirely, minimizing latency and eliminating switch CPU overhead on high-throughput uplinks.
Protecting the CPU
Because ARP inspection sends ARP packets to the switch CPU for validation, a flood of ARP traffic is also a CPU-protection concern. AOS-CX protects its control plane with control-plane policing (CoPP) and lets you cap broadcast traffic per port with rate-limit broadcast <rate> pps; there is no separate ARP-inspection rate-limit command to memorize for this exam.
Technical Comparison: DHCP Snooping vs. Dynamic ARP Inspection
| Technical Dimension | DHCP Snooping | Dynamic ARP Inspection (DAI) |
|---|---|---|
| Primary Threat Mitigated | Rogue DHCP servers, DHCP starvation | ARP poisoning, Man-in-the-Middle (MitM) snooping |
| Layer of Operation | Layer 7 payload inside UDP datagrams (Ports 67/68) | Layer 2/Layer 3 ARP protocol packets (EtherType 0x0806) |
| Inspection Mechanism | Filters server responses on untrusted ports | Validates Sender MAC/IP against binding table |
| Database Dependency | Creates and maintains the binding database | Dependent on the DHCP Snooping database (or static bindings) |
| Untrusted Port Behavior | Drops DHCPOFFER, DHCPACK, DHCPNAK | Drops invalid ARP frames missing from binding table |
| Trusted Port Behavior | Permits all DHCP requests and server responses | Permits all ARP frames without database validation |
AOS-CX Configuration Commands and Verification
The following AOS-CX 10.14 configuration enables DHCP snooping and Dynamic ARP Inspection on VLANs 10 and 20 and trusts the aggregation uplink. (Releases before 10.14 used the keyword dhcpv4-snooping.)
switch# configure terminal
! Step 1: Globally enable DHCP Snooping, then enable it per VLAN (VLAN context)
switch(config)# dhcp-snooping
switch(config)# vlan 10
switch(config-vlan-10)# dhcp-snooping
switch(config-vlan-10)# arp inspection
switch(config-vlan-10)# exit
switch(config)# vlan 20
switch(config-vlan-20)# dhcp-snooping
switch(config-vlan-20)# arp inspection
switch(config-vlan-20)# exit
! Step 2: Configure the Uplink Port to Aggregation/Core Switch as Trusted
switch(config)# interface 1/1/48
switch(config-if)# description Uplink-to-Campus-Core
switch(config-if)# no routing
switch(config-if)# vlan trunk allowed 10,20
switch(config-if)# dhcp-snooping trust
switch(config-if)# arp inspection trust
switch(config-if)# exit
! Step 3: Edge access ports stay untrusted (the default)
switch(config)# interface 1/1/1-1/1/24
switch(config-if-<1/1/1-1/1/24>)# no routing
switch(config-if-<1/1/1-1/1/24>)# vlan access 10
switch(config-if-<1/1/1-1/1/24>)# exit
Essential Verification Commands
| Verification Command | Operational Diagnostic Output |
|---|---|
show dhcp-snooping | Displays global DHCP snooping status, enabled VLANs, and settings such as Option 82. |
show dhcp-snooping binding | Lists active client bindings: MAC address, IP address, lease duration, VLAN, and interface. |
show arp inspection interface | Shows which interfaces are trusted or untrusted for ARP inspection. |
show arp inspection statistics | Displays packet counters for forwarded, dropped, and rate-limited ARP frames. |
show arp inspection vlan | Details per-VLAN ARP inspection status. |
Common Exam Traps
- DAI Dependency on DHCP Snooping: A classic exam question asks why legitimate dynamic clients lose network connectivity immediately after enabling DAI. If an administrator enables DAI before DHCP Snooping has populated the binding database, the switch drops all client ARP requests because no bindings exist! DHCP Snooping must be active and populated first.
- Omitting Uplink Trust: Forgetting to configure
dhcp-snooping truston switch uplinks prevents all downstream clients from receiving IP addresses because legitimateDHCPOFFERandDHCPACKpackets from the core DHCP server are dropped at the access switch uplink. - Untrusted Port Misconceptions: Untrusted ports do not block all DHCP traffic; they specifically permit client-originated requests (
DHCPDISCOVER,DHCPREQUEST) and block server-originated responses.
A network administrator enables DHCP Snooping globally and on VLAN 10 across an AOS-CX access switch. What action does the switch perform when a user workstation connected to port 1/1/5 transmits a DHCP Discover packet?
The switch immediately drops the packet because all untrusted ports discard both client and server DHCP messages by default
The switch converts the DHCP Discover packet into a unicast frame and forwards it only to the switch management IP
The switch error-disables port 1/1/5 until the administrator designates the interface as a trusted DHCP snooping port
The switch forwards the DHCP Discover packet because client-originated DHCP requests are permitted on untrusted ports
An administrator configures Dynamic ARP Inspection (DAI) on an AOS-CX switch for VLAN 20 without first enabling DHCP Snooping or configuring static IP-to-MAC bindings. What operational issue will occur on the campus network?
All connected client devices will bypass DAI inspection and broadcast unauthenticated ARP frames across the entire VLAN
The switch will drop all legitimate client ARP requests and replies because the underlying validation database is completely empty
The switch will dynamically convert all access ports into routed Layer 3 interfaces to bypass ARP resolution
The switch control plane CPU will immediately crash due to an infinite spanning tree topology recalculation loop
When deploying DHCP Snooping and Dynamic ARP Inspection on an Aruba AOS-CX access switch, which configuration command must be applied to the uplink interface connecting to the campus core router?
switch(config-if)# rate-limit broadcast 100 pps switch(config-if)# lldp med network-policy
switch(config-if)# dhcp-snooping trust switch(config-if)# arp inspection trust
switch(config-if)# port-access port-security violation shutdown
switch(config-if)# no arp inspection switch(config-if)# no dhcp-snooping
Sections you finish are checked off in the contents.