- cEnable DHCP snooping globally.
- Select Security > Control > DHCP Snooping Global Configuration.
A screen similar to the following displays.

- For DHCP Snooping Mode, select the Enable radio button.
- Click Apply.
- Select Security > Control > DHCP Snooping Global Configuration.
- Enable DHCP snooping in a VLAN.
- Select Security > Control > DHCP Snooping Global Configuration.
A screen similar to the following displays.

- In the VLAN ID field, enter 1.
- In the the DHCP Snooping Mode field, select Enable.
A screen similar to the following displays.

- Select Security > Control > DHCP Snooping Global Configuration.
- Configure the port through which the DHCP server is reached as trusted.
Here interface 1/0/1 is trusted.
- Select Security > Control > DHCP Snooping Interface Configuration.
A screen similar to the following displays.
- Select the check box for Interface 1/0/1.
- For Interface 1/0/1, set the Trust Mode as Enable.
- Click Apply. A screen similar to the following displays.

- Select Security > Control > DHCP Snooping Interface Configuration.
- View the DHCP Snooping Binding table.
- Select Security > Control > DHCP Snooping Binding Configuration.
A screen similar to the following displays.

- Select Security > Control > DHCP Snooping Binding Configuration.
- Enable ARP Inspection in VLAN 1.
- Select Security > Control > Dynamic ARP Inspection > DAI VLAN Configuration.
A screen similar to the following displays.
- In the VLAN ID field, enter 1.
- In the Dynamic ARP Inspection field, select Enable.
A screen similar to the following displays.
- Click Apply.
A screen similar to the following displays.
Note: Make sure the administrator PC has a DHCP snooping entry or can access the device through the trusted port for ARP. Otherwise, you might get disconnected from the device.
- Select Security > Control > Dynamic ARP Inspection > DAI VLAN Configuration.
- Configure port 1/0/1 as trusted.
- Select Security > Control > Dynamic ARP Inspection > DAI Interface Configuration.
- Select the Interface 1/0/1 check box.
- For the Trust Mode, select Enable.
- Click Apply.
A screen similar to the following displays.
For more information, see the following support articles:
- How do I configure static mapping using CLI commands on my managed switch?
- How do I configure static mapping using the web interface on my managed switch?
- What is Dynamic ARP inspection (DAI) and how does it work with my managed switch?
- How do I configure Dynamic ARP inspection (DAI) using CLI commands on my managed switch?
This article applies to the following managed switches and their respective firmware:
- M5300 - firmware version 10.0.0.x
-
- M5300-28G (GSM7228S)
- M5300-5G (GSM7252S)
- M5300-28G3 (GSM7328Sv2h2)
- M5300-52G3 (GSM7352Sv2h2)
- M5300-28G_POE+ (GSM7228PSv1h2)
- M5300-52G-POE+ (GSM7252PSv1h2)
- M5300-28GF3 (GSM7328FSv2)
- M4100 - firmware version 10.0.1.x
-
- M4100-26G (GSM7224v2h2)
- M4100-50G (GSM7248v2h2)
- M4100-26G-POE (GSM7226Pv1h1)
- M4100-50G-POE+ (GSM7248Pv1h1)
- M4100-26G-POE (FSM7226Pv1h1)
- M4100-50-POE (FSM7250Pv1h1)
- M4100-D12G (GSM5212v1h1)
- M4100-D10-POE (FSM5210Pv1h1)
- M7100 - firmware version 10.0.1.x
-
- M7100-24X (XSM7224)
- XSM7224S - firmware version 9.0.1.x