Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
heyyo
Contributor

Ensuring that Clients will only be getting IPs from authorized DHCP server

Hi Team,

 

Wanted to work on protecting the network from DHCP snooping. FortiGate acts as DHCP server. The plan is to block DHCP request from malicious or unauthorized DHCP server. How can this be achieved?

 

Note that I do not have a FortiSwitch in place.

 

Will using a local in policy to block the traffic help?

 

Thank you in advance!

2 REPLIES 2
sw2090
SuperUser
SuperUser

Since DHCP is udp broadcasting that can only work within a subnet/Interface (except if you relay it) this is so called net-internal-traffic. That will not hit any policy. Your FGT will just receive the broadcasted DHCPDISCOVER and answers it with a DHCPOFFER. 

I don't think there is any way to filter that.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
AEK
SuperUser
SuperUser

Hi Heyyo

You just need to enable and configure DHCP snooping on your access switch.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors