Configuring DHCP Snooping

DHCP snooping can be enabled on VLANs, after which the trust setting of ports connected to a DHCP server must be changed to trusted. DHCP packets for a VLAN with DHCP snooping enabled are inspected.
Note: DHCP snooping is disabled by default. When enabled, the trust setting of ports is "untrusted" by default. DHCP snooping must be enabled on the client and the DHCP server VLANs.
Note: DHCP Snooping can be configured for a VLAN or VLANS even before the VLAN or VLANS are created. VLANs and DHCP Snooping configurations on the VLANS are not automatically deleted when the VLAN is deleted.
  1. Enter global configuration mode by using the configure terminal command.
    device# configure terminal
  2. Enable DHCP snooping on a VLAN.
    device(config)# ip dhcp snooping vlan 2
  3. Change the trust setting of the ports that are connected to the DHCP server to trusted at the interface configuration level.
    device(config-if-e10000-1/1/1)# dhcp snooping trust
  4. If required, disable the learning of DHCP clients on ports at the interface configuration level. Disabling the learning of DHCP clients can be configured on a range of ports as well.
    device(config-if-e10000-1/1/1)# dhcp snooping client-learning disable
  5. Clear the DHCP binding database. You can remove all entries in the database or for a specific IP address only.
    The first command removes all entries from the DHCP binding database and the second removes entries for a specific IP address.
    device# clear dhcp
    device# clear dhcp 10.10.102.4
The following example configures VLAN 2 and VLAN 20, and enables DHCP snooping on the two VLANs.
device(config)# vlan 2
device(config-vlan-2)# untagged ethernet 1/1/3 to 1/1/4
device(config-vlan-2)# router-interface ve 2
device(config-vlan-2)# exit
device(config)# ip dhcp snooping vlan 2
device(config)# vlan 20
device(config-vlan-20)# untagged ethernet 1/1/1 to 1/1/2
device(config-vlan-20)# router-interface ve 20
device(config-vlan-20)# exit
device(config)# ip dhcp snooping vlan 20

On VLAN 2, client ports 1/1/3 and 1/1/4 are untrusted. By default all client ports are untrusted. Therefore, only DHCP client request packets received on ports 1/1/3 and 1/1/4 are forwarded. On VLAN 20, ports 1/1/1 and 1/1/2 are connected to a DHCP server. DHCP server ports are set to trusted.

device(config)# interface ethernet 1/1/1
device(config-if-e10000-1/1/1)# dhcp snooping trust
device(config-if-e10000-1/1/1)# exit
device(config)# interface ethernet 1/1/2
device(config-if-e10000-1/1/2)# dhcp snooping trust
device(config-if-e10000-1/1/2)# exit

Thus, DHCP server reply packets received on ports 1/1/1 and 1/1/2 are forwarded, and client IP address and MAC address binding information is collected. The example also sets the DHCP server address for the local relay agent.

device(config)# interface ve 2
device(config-vif-2)# ip address 10.20.20.1/24
device(config-vif-2)# ip helper-address 1 10.30.30.4
device(config-vif-2)# interface ve 20
device(config-vif-20)# ip address 10.30.30.1/24