Dhcp Snooping Configuration Guidelines - Cisco Catalyst 2928 Software Configuration Manual

Ios release 12.2(55)ez
Table of Contents

Advertisement

Chapter 19
Configuring DHCP Features and IP Source Guard Features
Table 19-1
Default DHCP Snooping Configuration
Feature
DHCP server
DHCP relay agent
DHCP packet forwarding address
Checking the relay agent information
DHCP relay agent forwarding policy
DHCP snooping enabled globally
DHCP snooping information option
DHCP snooping option to accept packets on
3
untrusted input interfaces
DHCP snooping limit rate
DHCP snooping trust
DHCP snooping VLAN
DHCP snooping MAC address verification
DHCP snooping binding database agent
1. The switch responds to DHCP requests only if it is configured as a DHCP server.
2. The switch relays DHCP packets only if the IP address of the DHCP server is configured on the SVI of the DHCP client.
3. Use this feature when the switch is an aggregation switch that receives packets with option-82 information from an edge switch.

DHCP Snooping Configuration Guidelines

These are the configuration guidelines for DHCP snooping.
OL-23389-01
Default Setting
Enabled in Cisco IOS software, requires configuration
Enabled
None configured
Enabled (invalid messages are dropped)
Replace the existing relay agent information
Disabled
Enabled
Disabled
None configured
Untrusted
Disabled
Enabled
Enabled in Cisco IOS software, requires configuration. This feature is
operational only when a destination is configured.
You must globally enable DHCP snooping on the switch.
DHCP snooping is not active until DHCP snooping is enabled on a VLAN.
Before globally enabling DHCP snooping on the switch, make sure that the devices acting as the
DHCP server and the DHCP relay agent are configured and enabled.
Before configuring the DHCP snooping information option on your switch, be sure to configure the
device that is acting as the DHCP server. For example, you must specify the IP addresses that the
DHCP server can assign or exclude, or you must configure DHCP options for these devices.
When configuring a large number of circuit IDs on a switch, consider the impact of lengthy character
strings on the NVRAM or the flash memory. If the circuit-ID configurations, combined with other
data, exceed the capacity of the NVRAM or the flash memory, an error message appears.
Before configuring the DHCP relay agent on your switch, make sure to configure the device that is
acting as the DHCP server. For example, you must specify the IP addresses that the DHCP server
can assign or exclude, configure DHCP options for devices, or set up the DHCP database agent.
If the DHCP relay agent is enabled but DHCP snooping is disabled, the DHCP option-82 data
insertion feature is not supported.
If a switch port is connected to a DHCP server, configure a port as trusted by entering the ip dhcp
snooping trust interface configuration command.
2
Catalyst 2928 Switch Software Configuration Guide
Configuring DHCP Snooping
1
2
2
19-9

Advertisement

Table of Contents
loading

Table of Contents