Configuration Notes and Feature Limitations for DHCP Snooping
The following notes, limitations, and restrictions apply to DHCP snooping:
- DHCP snooping is not supported on LAG ports.
- DHCP snooping is supported on Multi-Chassis Trunking (MCT) clients. DHCP snooping is not supported on the MCT peer for the MCT VLAN.
- If IP Source Guard (IPSG) is configured, the recommended maximum number of DHCP snooping entries for a stack is 8192. Although the maximum number of DHCP snooping entries for a stack can exceed 8192, system performance may go down once this number is exceeded. Refer to Configuration notes and feature limitations for IP Source Guard for more information on the recommended number of entries for RUCKUS ICX devices.
- DHCP snooping is not supported along with DHCP auto-configuration.
- When a client moves from one port to another port in the same VLAN, the old snoop entry for the client MAC address is automatically updated. This occurs even when the client acquires a new IP address.
- Duplicate IP entries across VLANs are allowed in the DHCP snooping table. When a client moves from one VLAN to another and acquires the same address, two snooping entries are maintained for the same MAC address and IP address.
- Layer 2 MAC movement is supported.
- ACLs are supported on member ports of a VLAN on which DHCP snooping and Dynamic ARP Inspection (DAI) are enabled. Refer to About client IP-to-MAC address mappings for more information.
- On ICX 8100 and ICX 8200 devices, DHCP snooping is supported at the Ethernet port level. DHCP snooping cannot be enabled on a port if it is enabled at a VLAN level that the port is part of. DHCP snooping cannot be enabled at the VLAN level if the DHCP snooping has been configured on the port already.
- For default VLAN ID changes, DHCP snooping must be re-applied on the new default VLAN. DHCP snooping is not automatically configured on the new default VLAN. Therefore, when DHCP Snooping is configured for the default VLAN (for example, VLAN 1), if the default VLAN is changed from VLAN 1 to VLAN 4000, the DHCP Snooping configurations remain configured on the old default VLAN 1. The DHCP Snooping configurations are not automatically configured on the new default VLAN 4000.
- DHCP snooping cannot be enabled for a VLAN that is a member of a VLAN group.
- DHCP snooping doesn't depend on MAC learning and MAC collisions. However, the total number of client(s) or host(s) in a system is limited by the system MAX limits for Layer 2 MAC Addresses.
- DHCP snooping entries on a member port of a VLAN are deleted except for flexible authentication enabled ports, if the port is removed from the membership of that VLAN.
- DHCP Snooping can be configured for a VLAN or VLANS even before the VLAN or VLANS are created. VLANs and DHCP Snooping configurations on the VLANS are not automatically deleted when the VLAN is deleted.
- When DHCP Snooping is enabled, client and server packets are not allowed on same port.
- DHCP snooping can be configured on a maximum of 511 VLANs.
- When configuring DHCP snooping on a range of VLANs or multiple VLANs, there cannot not be any VLAN in the range that is a member of a VLAN group or any reserved VLAN. Otherwise, configuration will be rejected for the entire range.
- The following limitation applies to ICX 8100
and ICX
8200 devices. To support DHCP snooping for Flexible authentication clients
in multiple untagged mode, DHCP snooping should also be enabled on the Flexible
authentication auth-default VLAN.
Example Flexible authentication configuration:
device# configure terminal device(config)# authentication device(config-authen)# auth-default-vlan 12 device(config-authen)# auth-mode multiple-untagged device(config-authen)# exit
device(config)# ip dhcp snooping vlan 12