IntermediatePublished 2026-07-04
DHCP Snooping Rate Limiting
Bundle lab
Harden the Layer-2 access edge by rate-limiting DHCP messages on untrusted ports. SW1 already has DHCP snooping enabled for VLAN 10 with the uplink trusted. Your task is to apply a per-interface rate limit on the host-facing access ports to blunt DHCP starvation attacks while leaving the trusted uplink unlimited.
Learning objectives
- Identify the DHCP snooping trust boundary on an access switch
- Apply deterministic DHCP rate limiting to untrusted access ports only
- Avoid rate-limiting the trusted uplink toward the legitimate DHCP server
- Verify configuration with show ip dhcp snooping and per-interface settings
- Explain how exceeding the limit triggers errdisable and how to observe it
Troubleshooting focus
- If hosts fail to obtain an address, confirm the uplink is trusted and not rate-limited
- If a port goes down unexpectedly, check for errdisable due to dhcp-rate-limit
- If show output does not list a rate on the access ports, the limit was not applied at interface scope
- If the DHCP server stops working, ensure the rate limit was not configured on the uplink
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the running-config — a change that only exists in a terminal session never reaches the grader.
- You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.