DHCP-security is not functioning correctly when applied to a leaf switch using EVPN/VXLAN. However, it is working as expected on downstream switches acting as access switches.
Symptoms
No DHCP snooping binding table entries present.
No logs for "AS_PKT_DHCP_DROPPED" appear for rogue DHCP servers, even when the interfaces are explicitly configured to "override as untrusted".
"AS_PKT_DHCP_DROPPED"
DHCP security is functioning correctly on other access switches.
Access port security features, such as DHCP snooping, are not supported with VXLAN. For more details, please refer to the following documentation:
https://www.juniper.net/documentation/us/en/software/junos/evpn/topics/concept/vxlan-constraints-qfx-series.html#:~:text=Access%20port%20security%20features%20such%20as%20the,*%20MAC%20limiting%20and%20MAC%20move%20limiting