Configuring DHCPv4 Snooping for Multi-VRF

DHCP supports Multi-VRF. You can deploy multiple Virtual Routing and Forwarding instances (VRFs) on a RUCKUS Ethernet switch. Each VLAN with a Virtual Ethernet (VE) interface is assigned to a VRF.
You can enable DHCP snooping on individual VLANs and assign any interface as the DHCP trust interface. If an interface is a tagged port in this VLAN, you can turn on the trust port per VRF, so that traffic intended for other VRF VLANs is not trusted.
  1. Enter global configuration mode using the configure terminal command.
    device# configure terminal
  2. Configure DHCP snooping on a specific VLAN.
    device(config)# ip dhcp snooping vlan 2
  3. Set the port as a trusted port. The trust port setting for DHCP snooping can be specified per VRF.
    device(config)# interface ethernet 1/1/4
    device(config-if-e10000-1/1/4)# dhcp snooping trust vrf vrf2
    The default trust setting for a port is untrusted. For ports that are connected to host ports, leave their trust settings as untrusted.
  4. Configure the IP helper address on the client port if the client and server are in the same VLAN and the client and server ports are Layer 3 interfaces with IP addresses.
    device(config)# interface ve 2
    device(config-vif-2)# ip helper-address 1 10.1.1.2
    If the client and server are in different VLANs, configure the server port as the trust port.
  5. Clear any entry specific to a VRF instance, as required.
    device(config)# clear dhcp 10.3.3.5 vrf one