Limit each access port to 2 MAC addresses with shutdown violation mode. 2. **DHCP Snooping** — Enable DHCP snooping on all VLANs and trust only the uplink port. 3. **Dynamic ARP Inspection** — Enable DAI with validation of source MAC, destination MAC, and IP. 4. **BPDU Guard** — Enable on all access