DHCP is broadcast traffic so it shouldn't matter where
you put the sniffer. The only thing is that you'll
need one one each subnet because you probably aren't
routing broadcast traffic between your VLAN's.


I'm looking at deploying DHCP Snooping in our
environment. I just want to make sure I've got this

We only have 1 DHCP server. So the only port that I
need to say is trusted is the one the DHCP Server is
connected to, right? I don't want anyone to be able
to deploy any rogue DHCP Servers in the network. We
are using VLANS, but I don't need to set the trunk
ports as trusted do I?

