Enterprise AV Home WiFi Mobile Wifi Support Shop Deals
  1. cEnable DHCP snooping globally.
    1. Select Security > Control > DHCP Snooping Global Configuration.

      A screen similar to the following displays.

      Image
       
    2. For DHCP Snooping Mode, select the Enable radio button.
    3. Click Apply.
       
  2. Enable DHCP snooping in a VLAN.
    1. Select Security > Control > DHCP Snooping Global Configuration.

      A screen similar to the following displays.

      Image
       
    2. In the VLAN ID field, enter 1.
    3. In the the DHCP Snooping Mode field, select Enable.

      A screen similar to the following displays.

      Image
       
  3. Configure the port through which the DHCP server is reached as trusted.

    Here interface 1/0/1 is trusted.
     
    1. Select Security > Control > DHCP Snooping Interface Configuration.

      A screen similar to the following displays.
      Image
    2. Select the check box for Interface 1/0/1.
    3. For Interface 1/0/1, set the Trust Mode as Enable.
    4. Click Apply. A screen similar to the following displays.

      Image
       
  4. View the DHCP Snooping Binding table.
    1. Select Security > Control > DHCP Snooping Binding Configuration.

      A screen similar to the following displays.

      Image
       
  5. Enable ARP Inspection in VLAN 1.
    1. Select Security > Control > Dynamic ARP Inspection > DAI VLAN Configuration.

      A screen similar to the following displays.

      Image
       
    2. In the VLAN ID field, enter 1.
    3. In the Dynamic ARP Inspection field, select Enable.

      A screen similar to the following displays.

      Image
       
    4. Click Apply.

      A screen similar to the following displays.

      Image
       
    Now all the ARP packets received on the ports that are member of the VLAN are copied to the CPU for ARP inspection. If there are trusted ports, you can configure them as trusted in the next step. ARP packets received on the trusted ports are not copied to the CPU.

    Note: Make sure the administrator PC has a DHCP snooping entry or can access the device through the trusted port for ARP. Otherwise, you might get disconnected from the device.
     
  6. Configure port 1/0/1 as trusted.
    1. Select Security > Control > Dynamic ARP Inspection > DAI Interface Configuration.
    2. Select the Interface 1/0/1 check box.
    3. For the Trust Mode, select Enable.
    4. Click Apply.

      A screen similar to the following displays.

      Image
       
    Now ARP packets from the DHCP client will go through; however ARP packets from the static client are dropped, since it does have a DHCP snooping entry. It can be overcome by static configuration.

 


For more information, see the following support articles:

 

 

 

 

 

This article applies to the following managed switches and their respective firmware:

 

 

  • M5300 - firmware version 10.0.0.x
    • M5300-28G (GSM7228S)
    • M5300-5G (GSM7252S)
    • M5300-28G3 (GSM7328Sv2h2)
    • M5300-52G3 (GSM7352Sv2h2)
    • M5300-28G_POE+ (GSM7228PSv1h2)
    • M5300-52G-POE+ (GSM7252PSv1h2)
    • M5300-28GF3 (GSM7328FSv2)
  • M4100 - firmware version 10.0.1.x
    • M4100-26G (GSM7224v2h2)
    • M4100-50G (GSM7248v2h2)
    • M4100-26G-POE (GSM7226Pv1h1)
    • M4100-50G-POE+ (GSM7248Pv1h1)
    • M4100-26G-POE (FSM7226Pv1h1)
    • M4100-50-POE (FSM7250Pv1h1)
    • M4100-D12G (GSM5212v1h1)
    • M4100-D10-POE (FSM5210Pv1h1)
  • M7100 - firmware version 10.0.1.x
    • M7100-24X (XSM7224)
  • XSM7224S - firmware version 9.0.1.x
Last Updated:07/07/2025 | Article ID: 21810

Our team is here to help!

Phone
Chat
Email