Harden the Layer-2 access edge by enabling DHCP Snooping on a single access switch and placing the trust boundary only toward the legitimate DHCP server/gateway. Validate with show commands and end-host connectivity.
Start here — freeLayer 2 Security Hardening
Eight hands-on labs — DHCP snooping, Dynamic ARP Inspection, protected ports, and errdisable recovery — defending the switch access edge.
Topics
What you'll learn
- Explain the purpose of DHCP Snooping and the trust boundary on an access switch
- Enable DHCP Snooping globally and for a specific VLAN
- Trust only the uplink interface toward the legitimate DHCP server
- Verify DHCP Snooping operational status and bindings
- Identify the DHCP snooping trust boundary on an access switch
- Apply deterministic DHCP rate limiting to untrusted access ports only
- Avoid rate-limiting the trusted uplink toward the legitimate DHCP server
- Verify configuration with show ip dhcp snooping and per-interface settings
Included labs
Harden the Layer-2 access edge by rate-limiting DHCP messages on untrusted ports. SW1 already has DHCP snooping enabled for VLAN 10 with the uplink trusted. Your task is to apply a per-interface rate limit on the host-facing access ports to blunt DHCP starvation attacks while leaving the trusted uplink unlimited.
View lab detailsHarden the Layer-2 access edge by enabling Dynamic ARP Inspection (DAI) on a single access switch. DHCP Snooping is already in place and the uplink toward the DHCP server/gateway is trusted. Your job: enable DAI for VLAN 10 and trust the uplink so ARP on host-facing ports is validated against the DHCP Snooping bindings.
View lab detailsHarden Dynamic ARP Inspection (DAI) on an access switch by enabling additional packet validation checks: source MAC, destination MAC, and IP sanity. The uplink toward the DHCP server/gateway is trusted, access ports are untrusted. DHCP Snooping and baseline DAI are already enabled for VLAN 10; your task is to add the global DAI validation knobs and verify the change deterministically via show commands.
View lab detailsHarden the campus access edge by isolating same-switch hosts using protected ports. You will configure switchport protected on both host-facing access interfaces so PC1 and PC2 cannot communicate at Layer 2, while all endpoints still reach the default gateway R1. This is a deterministic Layer-2 security control that mimics lightweight private-VLAN isolation on a single switch. Focus is on SW1 only; R1 and hosts are pre-provisioned.
View lab detailsHarden the Layer-2 access edge by deploying a unified trust boundary for DHCP Snooping and Dynamic ARP Inspection (DAI) on a single access switch. R1 is both the default gateway and DHCP server for VLAN 10. You will enable DHCP Snooping and DAI globally for VLAN 10 and set the same uplink interface as trusted for both features, leaving host-facing access ports untrusted. This lab emphasizes the dependency and synergy between DHCP Snooping and DAI for blocking rogue DHCP/ARP activity. Grade scope: SW1 config only.
View lab detailsLayer 2 Security Hardening, Lab 9/10. You will enable automatic errdisable recovery on a campus access switch so ports shut down by Layer-2 security (Dynamic ARP Inspection, DHCP rate-limit, or storm control) can return to service automatically after a safe interval. The switch already enforces DHCP snooping with a correct trust boundary, DAI validation, and broadcast/multicast/unicast storm-control with shutdown actions. Your job: turn on errdisable auto-recovery for arp-inspection, dhcp-rate-limit, and storm-control, and set the interval to 60 seconds. Verify with show errdisable recovery.
View lab detailsAdvanced Layer-2 security capstone. Neither PC on the access switch can get an address, and the help desk has already 'checked the DHCP server'. You get the symptoms and the requirements — no fault list. Work from show output to find every misconfiguration across the switch and the router, repair them, and prove both hosts recover. Several faults are layered: fixing the first one changes the symptom without ending the outage.
View lab detailsLearn this topic free first
Start with the free study hub and guides, then practice the same topics on real Cisco IOS.
Frequently asked questions
What's included in the Layer 2 Security Hardening bundle?
8 hands-on, auto-graded CCNA labs spanning 12 topics — each one a real Cisco Modeling Labs scenario you build on Cisco IOS.
Can I buy this bundle?
No — a subscription is the only plan we sell, and it includes every lab in this bundle for as long as it's active. Anyone who bought this bundle previously keeps it: every lab stays downloadable and gradable, permanently.
Do I need my own Cisco CML to run these labs?
Yes — each lab is a Cisco Modeling Labs (CML) topology you import and build on real Cisco IOS, and the CML free tier is enough. You download the topology and lab guide, then build it yourself.
How does the grading work?
Every lab ships as a problem to solve. You build it in CML, then submit your config to grade it against the answer key — you get a pass/fail on each objective, so you know exactly what's right and what to fix instead of guessing.
Which certification is this bundle for?
CCNA. The labs are sequenced to build the hands-on configuration and troubleshooting skills CCNA candidates are expected to demonstrate on real gear.