Configuring DHCP Snooping
- Enter global configuration mode
by using the
configure terminalcommand. -
Updates to this step to include the port level option for 8200Enable DHCP snooping.
- Change the trust setting of the ports that are connected to the DHCP server to trusted at the interface configuration level.
- If required, disable the learning of DHCP clients on ports at the interface configuration level. Disabling the learning of DHCP clients can be configured on a range of ports as well.
- Clear the DHCP binding database. You can remove all entries in the database or for a specific IP address only.
device(config)# vlan 2 device(config-vlan-2)# untagged ethernet 1/1/3 to 1/1/4 device(config-vlan-2)# interface ve 2 device(config-vlan-2)# exit device(config)# ip dhcp snooping vlan 2 device(config)# vlan 20 device(config-vlan-20)# untagged ethernet 1/1/1 to 1/1/2 device(config-vlan-20)# interface ve 20 device(config-vlan-20)# exit device(config)# ip dhcp snooping vlan 20
On VLAN 2, client ports 1/1/3 and 1/1/4 are untrusted. By default all client ports are untrusted. Therefore, only DHCP client request packets received on ports 1/1/3 and 1/1/4 are forwarded. On VLAN 20, ports 1/1/1 and 1/1/2 are connected to a DHCP server. DHCP server ports are set to trusted.
device(config)# interface ethernet 1/1/1 device(config-if-e10000-1/1/1)# dhcp snooping trust device(config-if-e10000-1/1/1)# exit device(config)# interface ethernet 1/1/2 device(config-if-e10000-1/1/2)# dhcp snooping trust device(config-if-e10000-1/1/2)# exit
Thus, DHCP server reply packets received on ports 1/1/1 and 1/1/2 are forwarded, and client IP address and MAC address binding information is collected. The example also sets the DHCP server address for the local relay agent.