Description

DHCP-security is not functioning correctly when applied to a leaf switch using EVPN/VXLAN. However, it is working as expected on downstream switches acting as access switches.

Symptoms

Symptoms

 

  • No DHCP snooping binding table entries present.

  • No logs for "AS_PKT_DHCP_DROPPED" appear for rogue DHCP servers, even when the interfaces are explicitly configured to "override as untrusted".

  • DHCP security is functioning correctly on other access switches.

 

Solution

Access port security features, such as DHCP snooping, are not supported with VXLAN. For more details, please refer to the following documentation:

 

https://www.juniper.net/documentation/us/en/software/junos/evpn/topics/concept/vxlan-constraints-qfx-series.html#:~:text=Access%20port%20security%20features%20such%20as%20the,*%20MAC%20limiting%20and%20MAC%20move%20limiting

Modification History

2026-02-06 : Article Created