DHCP Snooping, DAI & WLAN Security
CCNA 200-301 v2.0 · Live Feb 3, 2027 (v1.1 valid through Feb 2, 2027) Cisco Packet Tracer
مقصدObjectiveObjective
اس لیب میں آپ DHCP snooping اور DAI کانفیگر کرنا سیکھیں گے، اور WLAN security (WPA2/3) کے concepts سمجھیں گے۔Is lab mein aap DHCP snooping aur DAI configure karna seekhenge, aur WLAN security (WPA2/3) ke concepts samjhenge.In this lab you'll configure DHCP snooping and DAI, and understand WLAN security (WPA2/3) concepts.
آسان مثالSimple AnalogySimple Analogy
سوچو کہ کوئی جھوٹا ڈاکیہ آپ کے محلے میں آ کر کہتا ہے 'میں سرکاری دفتر ہوں، مجھے اپنے خط دے دو' — اور لوگ دے بھی دیتے ہیں! DHCP snooping وہ چوکیدار ہے جو کہتا ہے: 'دفتر صرف اس دروازے سے آئے گا (trusted port)، باقی سب دروازوں سے آنے والے دفتر جھوٹے ہیں۔' DAI (Dynamic ARP Inspection) اس کا ساتھی ہے جو جھوٹے پتے (ARP spoofing) پکڑتا ہے۔ WiFi میں WPA2/WPA3 گھر کے دروازے کا تالا ہے — جتنا نیا، اتنا مضبوط۔Socho ke koi jhoota dakiya aapke mohalle mein aa kar kehta hai 'main sarkari daftar hun, mujhe apne khat de do' — aur log de bhi dete hain! DHCP snooping woh chowkidar hai jo kehta hai: 'daftar sirf is darwaze se aayega (trusted port), baqi sab darwazon se aane wale daftar jhoote hain.' DAI (Dynamic ARP Inspection) uska saathi hai jo jhoote pate (ARP spoofing) pakarta hai. WiFi mein WPA2/WPA3 ghar ke darwaze ka taala hai — jitna naya, utna mazboot.Imagine a fake postman comes to your neighborhood saying 'I'm the government office, give me your letters' — and people actually hand them over! DHCP snooping is the guard who says: 'the office only comes through this door (trusted port); any office coming from other doors is fake.' DAI (Dynamic ARP Inspection) is his partner who catches fake addresses (ARP spoofing). In WiFi, WPA2/WPA3 is the lock on your home's door — the newer, the stronger.
سیٹ اپLab SetupLab Setup
SW1: Fa0/1 = DHCP server (trusted)، Fa0/2-10 = clients (untrusted, VLAN 10)۔ Devices: 1x Switch 2960 (SW1), 1x Router (DHCP server), 3x PC۔ PCs پر DHCP (automatic) رکھو۔ Rogue DHCP test کے لیے ایک PC پر DHCP سرور بنا کر دیکھو کہ snooping روکتا ہے۔SW1: Fa0/1 = DHCP server (trusted), Fa0/2-10 = clients (untrusted, VLAN 10). Devices: 1x Switch 2960 (SW1), 1x Router (DHCP server), 3x PC PCs par DHCP (automatic) rakho. Rogue DHCP test ke liye ek PC par DHCP server bana kar dekho ke snooping rokta hai.SW1: Fa0/1 = DHCP server (trusted), Fa0/2-10 = clients (untrusted, VLAN 10). Devices: 1x Switch 2960 (SW1), 1x Router (DHCP server), 3x PC. Keep DHCP (automatic) on the PCs. For a rogue DHCP test, build a DHCP server on one PC and see that snooping blocks it.
اقداماتStepsSteps
Step 1
SW1 پر DHCP Snooping۔ پہلے DHCP snooping آن کرو اور VLAN 10 پر لگاؤ۔SW1 par DHCP Snooping. Pehle DHCP snooping on karo aur VLAN 10 par lagao.DHCP snooping on SW1. First enable DHCP snooping and apply it to VLAN 10.
enable configure terminal ip dhcp snooping ip dhcp snooping vlan 10
Step 2
پھر DHCP سرور کی طرف جانے والے port (Fa0/1) کو trusted بناؤ — باقی سب untrusted۔Phir DHCP server ki taraf jane wale port (Fa0/1) ko trusted banao — baqi sab untrusted.Then mark the port toward the DHCP server (Fa0/1) as trusted — all others untrusted.
interface fa0/1 ip dhcp snooping trust exit
Step 3
Rate limit سے DHCP starvation attack روکتا ہے۔Rate limit se DHCP starvation attack rokta haiRate limiting stops DHCP starvation attacks.
interface range fa0/2 - 10 ip dhcp snooping limit rate 10 exit
Step 4
DAI آن کرو۔ DAI DHCP snooping کی binding table استعمال کر کے جھوٹے ARP packets پکڑتا ہے۔DAI on karo. DAI DHCP snooping ki binding table istemal kar ke jhoote ARP packets pakarta hai.Enable DAI. DAI uses DHCP snooping's binding table to catch fake ARP packets.
ip arp inspection vlan 10
Step 5
Server/uplink والا port trusted، باقی untrusted۔Server/uplink wala port trusted, baqi untrustedThe server/uplink port is trusted, the rest untrusted.
interface fa0/1 ip arp inspection trust exit
Step 6
Testing: PC کو IP ملنا چاہیے (trusted port سے)۔Testing: PC ko IP milna chahiye (trusted port se).Testing: the PC should get an IP (via the trusted port).
Step 7
پھر ایک PC پر rogue DHCP سرور آن کرو — دوسرے PCs کو اس سے IP نہیں ملنا چاہیے۔Phir ek PC par rogue DHCP server on karo — doosre PCs ko us se IP NAHI milna chahiye.Then start a rogue DHCP server on one PC — the other PCs should NOT get an IP from it.
تصدیقVerifyVerify
show ip dhcp snooping سے status دیکھو۔ show ip dhcp snooping binding سے leases دیکھو۔show ip dhcp snooping se status dekho. show ip dhcp snooping binding se leases dekho.Check status with show ip dhcp snooping. Check leases with show ip dhcp snooping binding.
show ip dhcp snooping show ip dhcp snooping binding
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ Snooping آن کرتے ہی کسی کو IP نہیں مل رہا۔Snooping on karte hi kisi ko IP nahi mil raha.As soon as snooping is on, nobody gets an IP.
✅ DHCP سرور کی طرف جانے والا port 'ip dhcp snooping trust' سے trusted ہونا چاہیے، ورنہ اصلی سرور کے replies بھی drop ہوں گے۔DHCP server ki taraf jane wala port 'ip dhcp snooping trust' se trusted hona chahiye, warna asli server ke replies bhi drop honge.The port toward the DHCP server must be trusted with 'ip dhcp snooping trust', otherwise even the real server's replies get dropped.
⚠️ DAI کام نہیں کر رہا۔DAI kaam nahi kar raha.DAI isn't working.
✅ DAI کے لیے DHCP snooping آن ہونا ضروری ہے کیونکہ DAI اسی کی binding table استعمال کرتا ہے۔DAI ke liye DHCP snooping on hona zaroori hai kyunke DAI usi ki binding table istemal karta hai.DAI requires DHCP snooping to be on, because DAI uses its binding table.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ WPA2 اور WPA3 میں فرق؟WPA2 aur WPA3 mein farq?What's the difference between WPA2 and WPA3?
WPA2 میں AES encryption ہے، WPA3 میں اور مضبوط (SAE handshake, forward secrecy)۔ Exam میں WPA3 کو بہتر جواب لکھو۔WPA2 mein AES encryption hai, WPA3 mein aur mazboot (SAE handshake, forward secrecy). Exam mein WPA3 ko behtar jawab likho.WPA2 uses AES encryption; WPA3 is stronger (SAE handshake, forward secrecy). For the exam, WPA3 is the better answer.