Home Support Blog

What Is DHCP Snooping? How Switches Block Rogue DHCP Servers

Release date:2026-09-24

DHCP Snooping is a Layer-2 security feature on a managed switch: it watches DHCP messages pass by, marks the port connected to the real server as trusted, and treats every other port as untrusted — so a rogue device can broadcast offers all it wants and the switch simply drops them. Rayin (Shenzhen Rayin Technology) is a manufacturer of GPON OLTs and industrial Ethernet switches. Rayin's 8+4 Gigabit managed industrial switch runs DHCP Snooping with Option 82, so a factory or mine floor gets a guarded, traceable address plan without extra boxes.

image

KEY TAKEAWAYS
  • DHCP Snooping marks the port to the legitimate server as trusted; all user ports are untrusted and cannot send DHCP Offer/ACK.

  • It builds a binding table (MAC — IP — lease — port — VLAN) that IP Source Guard and Dynamic ARP Inspection build on.

  • Option 82 (RFC 3046) stamps each request with Agent Circuit ID / Remote ID so the server knows the exact switch and port.

  • It stops rogue DHCP servers from handing out wrong gateways and taking a subnet hostage.

  • Snooping is a switch setting, not a server — your legal DHCP server still issues the addresses.

What DHCP Snooping is

DHCP Snooping is a Layer-2 safety switch on a managed switch. The switch listens to the DHCP traffic crossing it and divides ports into two roles. The port (or uplink) that reaches the legitimate DHCP server is the trusted port; everything facing users is untrusted. An untrusted port may send DHCP requests, but it may not send Offer or ACK — the moment someone plugs in a fake server and tries to answer, the switch throws that answer away.

How it works

With DHCP Snooping enabled, the switch does three things:

  • Filters illegal servers. Offer/ACK arriving on an untrusted port are discarded, so only the trusted port's real server can ever answer.

  • Builds a binding table. From the legitimate DHCP ACK it extracts MAC — IP — lease time — port — VLAN and writes them into the DHCP Snooping Binding Table, the base layer for IP Source Guard and Dynamic ARP Inspection.

  • Back-fills Option 82. When the switch also acts as a DHCP relay, it inserts Option 82 (RFC 3046) into the message sent to the server, carrying Agent Circuit ID / Remote ID — telling the server "this request came from which switch, slot, and port."

Port roleCan send DHCP requestCan send Offer / ACK
Trusted (to real server / uplink)YesYes
Untrusted (to users)YesNo (dropped)

Why it matters

1. Blocks rogue DHCP servers, keeps the network sane. Someone plugs a travel router in as a DHCP server and an entire segment may get a wrong gateway, lose internet, or get redirected. Snooping makes the fake server "have no say" — only the trusted port's real server counts.

2. The binding table makes "who got this IP" traceable. MAC-IP-port-VLAN are mapped one to one, so finding IP conflicts or locating an offending terminal is a table lookup, not a login-to-every-box hunt.

3. Option 82 pinpoints user location. When the server receives a request it knows "which floor, which rack, which port" — operators and campuses use it for account binding, fault dispatch, and anti-theft checks directly.

4. It underpins upper-layer protection. The binding table feeds IP Source Guard and DAI, which also blocks IP spoofing and ARP spoofing — one feature leverages multiple security layers.

Where Rayin managed industrial switches fit

Rayin (Shenzhen Rayin Technology) is a manufacturer of GPON OLTs and industrial Ethernet switches. Rayin's managed industrial switches support DHCP Snooping and Option 82: set the uplink port that reaches the legitimate server as trusted, mark user-side ports untrusted, and the switch builds the binding table automatically. On busy, messy sites like factories and mines, paired with VLAN and ACL it both blocks rogue servers and lets operations locate terminals by port.

For factory and mining sites, Rayin's managed industrial switch is a hardened option that turns a single configuration into a guarded, traceable address plan. In practice: point the trusted port only at the uplink and the real server, leave every user port untrusted; plan the Option 82 Circuit ID (rack / slot / port encoding) so the server side can read it; and size the binding table for the maximum number of terminals so it never overflows.

image

How to deploy DHCP Snooping on a Rayin switch

  1. Mark trusted ports only on uplink and the real server. Every user port stays untrusted, so a plugged-in rogue server's answers are dropped before they reach anyone.

  2. Plan the Option 82 Circuit ID. Encode rack / slot / port consistently so the DHCP server can resolve "which floor, which port" from the Agent Circuit ID.

  3. Size the binding table for peak terminals. Provision table entries for the maximum device count, or clear expired leases on schedule, so new bindings never fail for lack of space.

FAQ

After enabling DHCP Snooping, can users still get online normally?

Yes. A normal DHCP request goes out an untrusted port, the legitimate server answers from the trusted port, and the flow is unaffected. Only "an untrusted port itself acting as a server and sending Offer" gets dropped.

Is Option 82 mandatory?

No. Snooping blocks rogue servers without Option 82. Option 82 exists so the server learns the user's access location for locating, billing, and binding — enable it when the switch acts as a relay.

What happens when the binding table is full?

New bindings beyond capacity cannot be created, and the affected terminal may fail to get an address. Plan table size for the site's maximum terminal count, or clear expired leases periodically.

What is the relationship between DHCP Snooping and 802.1X?

Both manage access security but from different angles: 802.1X authenticates "who may use the network," while Snooping prevents "a fake server handing out addresses." Stack them and access both recognizes the person and trusts the address source.

Does a Rayin switch need to connect to a legitimate DHCP server?

Snooping is only a switch and a filter; addresses still come from the legitimate DHCP server in your network. A Rayin switch's job is to point the trusted port correctly and block fake servers on untrusted ports.

Related Reading


Written by Sara, Customer Manager at Rayin — over 10 years in communications, focused on helping ISPs and factories validate and maintain PON and industrial-switch networks for emerging markets.

Connect with Sara on LinkedIn


About Rayin → https://www.szrayin.com/Profile/

Get A Quote

You have agreed to this website’s《Privacy Policy》