DHCP Snooping

If I have DHCP configured on my switch, how do I configure DHCP snooping? I know that if you have a dhcp server on a switch port, that's where you apply the IP DHCP SNOOPING TRUST as well as on the links between switches and tot he router. If I don't have a physical DHCP server, how do I configure DHCP snooping?

Shark Attack
It does no matter if you have physical server or not. You mark port that is trusted - the port from which DHCP offer  will be received. DHCP offer can only came from trusted port, any other port if DHCP offer is received will be error-disabled.
Shark Attack
Well, if I have the below scope configured, which port do I mark as trusted? How do i know what port DHCP offer will be received from?

ip dhcp pool Guest-Pool

Since DHCP server is your switch, you would need just enable dhcp snooping globally and then to enable it on for VLAN.
If there are other switches connected to this one, it is easy know which port to configure for ip dhcp snooping - most likely trunks should be trusted ports on those switches, all other ports should stay untusted. :)

(config)#ip dhcp snooping  

(config)#ip dhcp snooping vlan 20

# sh ip dhcp snooping
Switch DHCP snooping is enabled
DHCP snooping is configured on following VLANs:
DHCP snooping is operational on following VLANs:
DHCP snooping is configured on the following L3 Interfaces:

Insertion of option 82 is enabled
   circuit-id default format: vlan-mod-port
   remote-id: 867e.0000.88db (MAC)
Option 82 on untrusted port is not allowed
Verification of hwaddr field is enabled
Verification of giaddr field is enabled
DHCP snooping trust/rate is configured on the following Interfaces:

Interface                  Trusted    Allow option    Rate limit (pps)
-----------------------    -------    ------------    ----------------

Cisco - ip dhcp snooping configuration

Shark Attack
Shark Attack
how do I set the port to be NOT trusted ?
You don't, all ports are untrusted except of ports that you configured as trusted ports.
Shark Attack
thats what I thought. thanks
