Solved

I need help blocking DHCP on a trunk port

Posted on 2008-10-02
8
1,830 Views
Last Modified: 2012-06-21
I have 2 Procurve switches connected via gbic fiber. Both switches have DHCP servers in the network segments they handle (10.10.20.x/16 and 10.10.30.x/16). Unfortunately sometimes clients attached to one switch grab an IP address from the dhcp server on the other switches network segment. In essence I need to block DHCP from going across that GBIC wire. How can I configure this?

Any help would really be appreciated.
0
Comment
Question by:vielmetter
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
8 Comments
 
LVL 3

Expert Comment

by:Brooklyn_Shogun
ID: 22626575
Hello:

From what I am seeing in your question:

"Both switches have DHCP servers in the network segments they handle (10.10.20.x/16 and 10.10.30.x/16)"

If this is the exact setup then your issue is that the network mask is wrong because the network ID would be 10.10.0.0.

1) Check that you have the DHCPs set to a subnet mask of 255.255.255.0
0
 
LVL 2

Author Comment

by:vielmetter
ID: 22627340
My DHCP's need to talk to each other, they are DC's and they need to be able to communicate with each other across a trust relationship.

Is there a way to make adjustments on the switch that will prevent these packets going back and fourth between switches and networks?
0
 
LVL 10

Accepted Solution

by:
kyleb84 earned 125 total points
ID: 22629649
What type of switches are they? 2600? 2800? Higher?

If they are, they'll do Routing, and since you can't do ACLs if you make each subnet a routable network, you'll retain your interconnectivity and stop DHCP being broadcast across each switch.

On your first switch, configure it similar to this
- Assuming 24 port switches, and your GBIC is port 24, and your default gateway isn't .254

(10.10.20.0/24)

vlan 1
 name "Network20"
 ip address 10.10.20.254/24
 untagged 1-23
 tagged 24

vlan 3
 name "Network30"
 ip address 10.10.30.253/24
 tagged 24

ip default-gateway x.x.x.x
---------------------

Second switch (10.10.30.0/24):

vlan 1
 name "Network20"
 ip address 10.10.20.253/24
 tagged 24

vlan 3
 name "Network30"
 ip address 10.10.30.254/24
 untagged 1-23
 tagged 24

ip default-gateway 10.10.20.254
------------------------

Set your DHCP servers, and your DC's etc to /24
Set your 10.10.20.0/24 DHCP range to have a default gateway of the Network20 switch 10.10.20.254
Set your 10.10.30.0/24 DHCP range to have a default gateway of the Network30 switch 10.10.30.254
Set your internet gateway to 10.10.20.x/24, and give it a route to the 10.10.30.0/24 network via the Network20 switch (10.10.20.254)
Set the x.x.x.x in your Network20 switch's config to your internet gateway (10.10.20.1?)

- Now DHCP will be blocked from going to either switch
- Your DC's (10.10.20.2 and 10.10.30.2 for example) are connected to their respective switch and they remain connected because their default route is their switch
- Everyone remains to have internet because the Network20 switch will forward on all packets to the default gateway (Your internet router).

-------------------------------

Either do all that, buy a Cisco 877 router to do ACLs, or just disable your DHCP on one DC.
0
Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

 
LVL 2

Author Comment

by:vielmetter
ID: 22629860
kyleb84, I like your solution and will credit you the points because I think this solution will work. I do have a cisco router with 2 ethernet interfaces. If I use it for to do ACL's (as you suggest above) how would I go about it? what would a basic acl look like to block DHCP? And if I do this aren't I limiting my connection between the two switches from 1000 (GBIC speed) to 100 (router ethernet port speed)? In any case, I'd be curious as to how to create an ACL that blocks DHCP on a cisco router, especially if if both networks are in the same subnet.
0
 
LVL 2

Author Closing Comment

by:vielmetter
ID: 31502464
Great answer! Not just an idea, but a clear concrete set of steps that will resolve the problem.
Thanks
0
 
LVL 10

Expert Comment

by:kyleb84
ID: 22629932
To give a better example, what model is the Cisco router?

The access list would look like this:

access-list 111 deny udp any eq bootps
access-list 111 deny udp any eq bootpc
access-list 111 permit ip any any

Assign it to an interface:

int Vlan1
 ip access-group 111

You would then have to put this router in-line between the switches, and yes, you would lose your Gigabit speeds, unless your DC's are on 100mbit and you throw it in between them and the switches (2 x ciscos required).

Depending on the model, you'd have to make both ports a member of a bridge to keep the same subnet across them.

But in any case, that'd be the general solution.



0
 
LVL 10

Expert Comment

by:kyleb84
ID: 22629972
Sorry, should add this command to the bottom of either Switch config to actually turn on routing.

ip routing
0
 
LVL 2

Author Comment

by:vielmetter
ID: 22662228
My procurve doesn't have the ip default-gateway 10.10.20.254 command. Do I just use 0.0.0.0 0.0.0.0 10.10.20.254 instead? or is that wrong?
0

Featured Post

Major Incident Management Communications

Major incidents and IT service outages cost companies millions. Often the solution to minimizing damage is automated communication. Find out more in our Major Incident Management Communications infographic.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Trunk Port 7 72
slow WAN performance - ESXi WAN vSwitch 27 64
Dell PowerConnect 2824 w/ two DHCP 6 67
Cisco 3650 switch 1G port to 10G port 6 42
I see many questions here on Experts Exchange regarding switch port configurations and trunks. This article is meant for beginners in the subject to help to get basic knowledge about Virtual Local Area Network (VLAN (http://en.wikipedia.org/wiki/Vir…
This tutorial will go through the steps required to write a script that will back up the configuration settings of a HP-ProCurve switch. You will need to get the following things to follow this tutorial: Telnet Scripting Tool e.g. TST10.exe …
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…
How to Install VMware Tools in Red Hat Enterprise Linux 6.4 (RHEL 6.4) Step-by-Step Tutorial

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question