Configuring DHCPv6 Snooping

DHCPv6 snooping must be enabled on VLANs, after which the trust setting of ports connected to a DHCPv6 server must be changed to trusted. DHCPv6 packets for a VLAN with DHCPv6 snooping enabled are inspected.
Note: DHCPv6 snooping is disabled by default and the trust setting of ports is untrusted by default. DHCPv6 snooping must be enabled on the client and the DHCPv6 server VLANs.
Note: DHCPv6 snooping can be configured for a VLAN or multiple VLANs even before the VLAN or multiple VLANs are created. DHCPv6 snooping configurations on the VLANs are not automatically deleted when the VLAN is deleted.
  1. Enter global configuration mode by using the configure terminal command.
    device# configure terminal
  2. Updates to this step to include the port level option for 8200
    Enable DHCPv6 snooping.
    1. For all devices, enable DHCPv6 snooping on a VLAN.
      device(config)# ipv6 dhcp6 snooping vlan 2
    2. Optionally, for ICX 8200 devices, enable DHCPv6 snooping at the port level.
      device(config)# interface ethernet 1/1/1
      device(config-if-e10000-1/1/1)# ipv6 dhcp6 snooping
  3. Change the trust setting of the ports that are connected to the DHCPv6 server to trusted at the interface configuration level.
    device(config)# interface ethernet 1/1/1
    device(config-if-e10000-1/1/1)# dhcp6 snooping trust
    Port 1/1/1 is connected to a DHCPv6 server. At the interface configuration level, the trust setting of port 1/1/1 is set to trusted.
  4. If required, on VLAN only, disable the learning of DHCPv6 clients on ports at the interface configuration level. Disabling the learning of DHCPv6 clients can be configured on a range of ports as well.
    device(config-if-e10000-1/1/1)# dhcp6 snooping client-learning disable
  5. Clear the DHCPv6 binding database. You can remove all entries in the database or entries for a specific IP address only.
    The first command removes all entries from the DHCPv6 binding database and the second removes entries for a specific IP address.
    device# clear ipv6 dhcp6 snooping
    device# clear ipv6 dhcp6 snooping 2001::2

The following example configures VLAN 10, and enables DHCPv6 snooping for the configured VLAN.

device(config)# vlan 10
device(config-vlan-10)# untagged ethernet 1/1/1 to 1/1/3
device(config-vlan-10)# exit
device(config)# ipv6 dhcp6 snooping vlan 10

On VLAN 10, client ports 1/1/2 and 1/1/3 are untrusted. By default, all client ports are untrusted. Only DHCPv6 client SOLICIT and REQUEST packets received on ports 1/1/2 and 1/1/3 are forwarded.

The following example sets the DHCPv6 server port as trusted.

device(config)# interface ethernet 1/1/1
device(config-if-e10000-1/1/1)# dhcp6 snooping trust
device(config-if-e10000-1/1/1)# exit

Port 1/1/1 is connected to a DHCPv6 server. The DHCPv6 server ADVERTISE and REPLY packets received on port 1/1/1 are forwarded.