Configuration Notes and Feature Limitations for DHCPv6 Snooping

The following configuration considerations apply to DHCPv6 snooping:

  • DHCPv6 snooping must be enabled on both client and server VLANs.
  • For default VLAN ID changes, DHCPv6 snooping must be re-applied on the new default VLAN. DHCPv6 snooping is not automatically configured on the new default VLAN. Therefore, when DHCPv6 snooping is configured for the default VLAN (for example, VLAN 1), if the default VLAN is changed from VLAN 1 to VLAN 4000, the DHCPv6 snooping configurations remain configured on the old default VLAN 1. The DHCPv6 snooping configurations are not automatically configured on the new default VLAN 4000.
  • When a client moves from one port to another port in the same VLAN, the old snoop entry for the client MAC address is automatically updated. This occurs even when the client acquires a new IPv6 address.
  • Duplicate IPv6 entries across VLANs are allowed in the DHCPv6 snooping table. When a client moves from one VLAN to another and acquires the same address, two snooping entries are maintained for the same MAC address and IP address.
  • Layer 2 MAC movement is supported.
  • DHCPv6 snooping cannot be enabled for a VLAN that is a member of a VLAN group.
  • When DHCPv6 snooping is enabled, replies are prevented from going out on DHCPv6 snooping trusted ports.
  • When configuring DHCPv6 snooping on a range of VLANs, no VLAN in the range can be a member of a VLAN group or any reserved VLAN. Otherwise, the configuration fails on the entire range.
  • If required, disable the learning of DHCPv6 clients on ports at the interface configuration level.
  • DHCPv6 snooping entries learned on a member port of VLAN are deleted, with the exception of flexible authentication enabled ports, if the port is removed from the membership of that VLAN.
  • DHCPv6 snooping can be configured for a VLAN or multiple VLANs even before the VLAN or VLANs are created. DHCPv6 snooping configurations on the VLANs are not automatically deleted when the VLAN is deleted.
  • When DHCPv6 snooping is enabled, client and server packets are not allowed on same port.
  • DHCP snooping can be configured on a maximum of 511 VLANs.
  • When configuring DHCPv6 snooping on a range of VLANs or multiple VLANs, there cannot not be any VLAN in the range that is a member of a VLAN group or any reserved VLAN. Otherwise, configurations fail on the entire range.
  • ACLs are supported on member ports of a VLAN on which DHCPv6 snooping is enabled. Refer to About client IP-to-MAC address mappings for more information.
  • The following limitation applies to ICX 8100 and ICX 8200 devices. To support DHCPv6 snooping for Flexible authentication clients in multiple untagged mode, DHCPv6 snooping should also be enabled on the Flexible authentication auth-default VLAN.

    Example Flexible authentication configuration:

    device# configure terminal
    device(config)# authentication
    device(config-authen)# auth-default-vlan 12
    device(config-authen)# auth-mode multiple-untagged
    device(config-authen)# exit
    

    Example DHCP configuration:

    device(config)# ip dhcp snooping vlan 12

    Example DHCPv6 configuration:

    device(config)# ipv6 dhcp6 snooping vlan 12