Configuring DHCP Snooping on Multiple VLANs
DHCP snooping can be enabled on multiple
VLANs using one command. The following task configures multiple VLANs and enables
DHCP
snooping on most of the configured VLANs using a single command.
Note: DHCP snooping can be configured on a maximum
number of 511 VLANs at one time.
Note: DHCP Snooping can be configured for
a VLAN or VLANS even before the VLAN or VLANS are created. VLANs and DHCP Snooping
configurations on the VLANS are not automatically deleted when the VLAN is
deleted.
Note: When configuring DHCP snooping on a range of VLANs or multi-VLAN, there cannot
not be any VLAN in the range that is a member of a VLAN group or any reserved
VLAN.
Otherwise, configurations fail on the entire range.
- Enter global configuration mode.
- Configure the port-based VLANs.
- Add port Ethernet 1/1/12 as a tagged port.
- Use the
exitcommand to return to global configuration mode. - Configure more port-based VLANs.
- Add port Ethernet 1/1/12 as a tagged port.
- Use the
exitcommand to return to global configuration mode. - Use the
ip dhcp snoopingcommand with the to keyword, specifying a VLAN range, to enable DHCP snooping on multiple VLANs. - Change the trust setting of the ports that are connected to the DHCP server to trusted at the interface configuration level.
The following example configures VLANs 100
through 200, and enables DHCP snooping on VLANs 100 through 150, VLAN 160, and
VLANs 170
through 200.
device# configure terminal device(config)# vlan 100 to 150 device(config-mvlan-100-150)# tagged ethernet 1/1/12 device(config-mvlan-100-150)# exit device(config)# vlan 151 to 200 device(config-mvlan-151-200)# tagged ethernet 1/1/12 device(config-mvlan-100-150)# exit device(config)# ip dhcp snooping vlan 100 to 150 160 170 to 200 device(config)# interface ethernet 1/1/12 device(config-if-e10000-1/1/12)# dhcp snooping trust