Hi Team,
Wanted to work on protecting the network from DHCP snooping. FortiGate acts as DHCP server. The plan is to block DHCP request from malicious or unauthorized DHCP server. How can this be achieved?
Note that I do not have a FortiSwitch in place.
Will using a local in policy to block the traffic help?
Thank you in advance!
Since DHCP is udp broadcasting that can only work within a subnet/Interface (except if you relay it) this is so called net-internal-traffic. That will not hit any policy. Your FGT will just receive the broadcasted DHCPDISCOVER and answers it with a DHCPOFFER.
I don't think there is any way to filter that.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Hi Heyyo
You just need to enable and configure DHCP snooping on your access switch.
User | Count |
---|---|
2331 | |
1262 | |
772 | |
453 | |
436 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.