Configuring DHCPv6 Snooping
DHCPv6 snooping must be enabled on VLANs, after which the trust setting of ports connected
to a DHCPv6 server must be changed to trusted. DHCPv6 packets for a VLAN with DHCPv6
snooping enabled are inspected.
Note: DHCPv6 snooping is disabled by default and the trust setting of ports is untrusted
by default. DHCPv6 snooping must be enabled on the client and the DHCPv6 server VLANs.
Note: DHCPv6 Snooping can be configured for a VLAN or VLANS even before the VLAN or
VLANS are created. VLANs and DHCPv6 Snooping configurations on the VLANS are not
automatically deleted when the VLAN is deleted.
- Enter global configuration mode
by using the
configure terminalcommand. - Enable DHCPv6 snooping on a VLAN.
- Change the trust setting of the ports that are connected to the DHCPv6 server to trusted
at the interface configuration level.
Port 1/1/1 is connected to a DHCPv6 server. The commands access the CLI to the interface configuration level of port 1/1/1 and set the trust setting of port 1/1/1 to trusted.
- If required, disable the learning of DHCPv6 clients on ports at the interface configuration level. Disabling the learning of DHCPv6 clients can be configured on a range of ports as well.
- Clear the DHCPv6 binding database. You can remove all entries in the database or for
a specific IP address only.
The first command removes all entries from the DHCPv6 binding database and the second removes entries for a specific IP address.
The following example configures VLAN 10, and enables DHCPv6 snooping for the configured VLANs.
device(config)# vlan 10 device(config-vlan-10)# untagged ethernet 1/1/1 to 1/1/3 device(config-vlan-10)# exit device(config)# ipv6 dhcp6 snooping vlan 10
On VLAN 10, client ports 1/1/2 and 1/1/3 are untrusted. By default, all client ports are untrusted. Only DHCPv6 client SOLICIT and REQUEST packets received on ports 1/1/2 and 1/1/3 are forwarded.
The following example sets the DHCPv6 server port as trusted.
device(config)# interface ethernet 1/1/1 device(config-if-e10000-1/1/1)# dhcp6 snooping trust device(config-if-e10000-1/1/1)# exit
Port 1/1/1 is connected to a DHCPv6 server. The DHCPv6 server ADVERTISE and REPLY packets received on port 1/1/1 are forwarded.