cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
655
Views
3
Helpful
6
Replies

WLC DHCP Proxy mode and DHCP Snooping on upstream switch

Hello,

is there an issue when we have WLC DHCP proxy mode and upstream switch with DHCP snooping enabled?

Based on docs, WLC in proxy mode changes giaddr field (and can insert option-82 as well) and switch ignores DHCP messages over untrusted ports if it has non-zero giaddr field or option-82 (like relay info inserted).

Then, it should be problematic for DHCP snooping enabled environment, right? We need to make trust WLC connected ports (which disables snooping checks for those ports, in reality) or configure L2 ports as ip dhcp relay trusted. Did anyone had

HTH,
Please rate and mark as an accepted solution if you have found any of the information provided useful.

6 Replies 6

ammahend
VIP
VIP

snooping dictates where offer comes from not where discover comes from, so dont think this should be an issue

-hope this helps-

No, snooping has some checks for client messages as well.

For example, when you have access and distro switch with both snooping enabled where access inserts option82, then distro switch ignores client messages. We normally either remove option82 on access OR allow it on untrusted port on distro switch.

I assume then same happens in WLC, but can not get confirmation since I dont have WLC Lab

HTH,
Please rate and mark as an accepted solution if you have found any of the information provided useful.

you are right you have to have ip dhcp snooping information option allow-untrusted.

by default its disabled. 

-hope this helps-

Rich R
VIP
VIP

DHCP proxy only applies to the old AireOS based WLCs which are almost end of life.  If you are designing for future then you should be looking at the 9800 series WLCs.

If you use 9800 series WLC as per the Best Practice guide (link below) then you should not configure SVI on the 9800 at all and leave the snooping/forwarding/relaying to the attached infrastructure.  If you do configure SVI with helper address/dhcp relay then it will be doing standards based DHCP relay not DHCP proxy.

Thank you, but since it is DHCP relay then giaddr will be modified and infrastructure dhcp snooping enabled switch will ignore these messages over untrusted.

Seems, if it is not bridge mode then ip dhcp snooping trust is needed

HTH,
Please rate and mark as an accepted solution if you have found any of the information provided useful.

Ip dhcp snooping trust toward wlc is not needed since the wlc is represent client here.

The modify of dhcp and add op82 is need I think.

Now 

Wlc add op82 send to SW (with dhcp snooping) what you need is 

Ip dhcp snooping information option allow-untrusted

Why untrust ? Since the port is untrust and wlc add op82 then this need.

Review Cisco Networking products for a $25 gift card