srg wrote: » OTOH I think you configure it without a trusted interface.. since the legit DHCP traffic originates 'inside' the switch. I'm not even sure you are able to configure a SVI as trusted interface, but I might be a little off on that one.