Enabling DHCP Snooping MAC Address Verification

The DHCP malformed packet coming from the client is blocked when DHCP snooping is enabled along with "ip dhcp snooping verify mac-address" MAC address verification command.
The MAC address verification command works only when DHCP snooping is enabled on the device.

Limitation: DHCP client and DHCP snooping device are connected on either sides of a relay. Source MAC address in the DHCP DISCOVER or DHCP REQUESTpacket will be the MAC address of the relay and the client hardware MAC address will be the MACaddress of the client. You must disable MAC address verification for the IP acquisition by the client to work properly.

  1. Enter global configuration mode by using the configure terminal command.
    device# configure terminal
  2. Enable MAC address verification.
    device(config)# ip dhcp snooping verify mac-address

    Note: DHCP snooping MAC address verification is disabled by default.

  3. (Optional) Disable DHCP snooping MAC address verification.
    device(config)# no ip dhcp snooping verify mac-address
device# configure terminal
device(config)# ip dhcp snooping verify mac-address