How DHCP Snooping Works

When enabled on a VLAN, DHCP snooping stands between untrusted ports (those connected to host ports) and trusted ports (those connected to DHCP servers). A VLAN with DHCP snooping enabled forwards DHCP request packets from clients and discards DHCP server reply packets on untrusted ports. DHCP server reply packets on trusted ports to DHCP clients are forwarded, as shown in the following figures.

DHCP Snooping at Work on an Untrusted Port

DHCP Snooping at Work on a Trusted Port

Note: Trusted client ports can lead to DHCP starvation and spoofing attacks. When DHCP snooping is enabled, DHCP request packets received on trusted ports are dropped.