Skip to main content
heyyo
Explorer III
May 7, 2025
Question

Ensuring that Clients will only be getting IPs from authorized DHCP server

  • May 7, 2025
  • 2 replies
  • 776 views

Hi Team,

 

Wanted to work on protecting the network from DHCP snooping. FortiGate acts as DHCP server. The plan is to block DHCP request from malicious or unauthorized DHCP server. How can this be achieved?

 

Note that I do not have a FortiSwitch in place.

 

Will using a local in policy to block the traffic help?

 

Thank you in advance!

2 replies

sw2090
SuperUser
SuperUser
May 7, 2025

Since DHCP is udp broadcasting that can only work within a subnet/Interface (except if you relay it) this is so called net-internal-traffic. That will not hit any policy. Your FGT will just receive the broadcasted DHCPDISCOVER and answers it with a DHCPOFFER. 

I don't think there is any way to filter that.

AEK
SuperUser
SuperUser
May 7, 2025

Hi Heyyo

You just need to enable and configure DHCP snooping on your access switch.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!