Default Configuration For Dhcp Snooping; Enabling Dhcp Snooping - Cisco WS-C6506 Software Manual

Catalyst 6500 series switch
Hide thumbs Also See for WS-C6506:
Table of Contents

Advertisement

Configuring DHCP Snooping on a VLAN
These sections describe how to configure DHCP snooping:

Default Configuration for DHCP Snooping

DHCP snooping is disabled by default.
DHCP-snooping option. If you want to change the default configuration values, see the
Snooping" section on page
Table 33-1
Option
DHCP-snooping host tracking
information option
DHCP-snooping limit rate
DHCP-snooping trust on a port
DHCP snooping on a VLAN
DHCP-snooping bindings-database
auto-save option
DHCP-snooping bindings-database
storage device and filename

Enabling DHCP Snooping

DHCP snooping is enabled on the VLANs through the security VLAN access control lists (VACLs).
DHCP snooping is enabled on a VLAN by adding a DHCP-snooping access control entry (ACE) to a
new or existing security ACL. You must determine where to position DHCP snooping in the ACL
depending on your policy for the DHCP packets. For example, if you want to deny the DHCP packets
that come from a certain host and perform DHCP snooping for the other DHCP packets, then you must
place a deny ACE before the DHCP-snooping ACE.
To enable DHCP snooping on a VLAN, perform this task in privileged mode:
Task
Step 1
Add DHCP snooping to the VACL.
Step 2
Configure the VACL to allow DHCP
snooping from all hosts.
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
33-4
Default Configuration for DHCP Snooping, page 33-4
Enabling DHCP Snooping, page 33-4
Enabling DHCP Snooping on a Private VLAN, page 33-5
Enabling the DHCP-Snooping Host-Tracking Information Option, page 33-5
Enabling the DHCP Snooping MAC-Address Matching Option, page 33-6
Configuration Examples for DHCP Snooping, page 33-7
33-4.
Default Configuration Values for DHCP Snooping
Chapter 33
Configuring DHCP Snooping and IP Source Guard
Table 33-1
shows the default configuration values for each
Default Value/State
Disabled.
1000 pps shared with ARP inspection and 802.1X-DHCP.
Rate limiting is supported on PFC2 and later versions.
Untrusted.
Disabled.
Disabled.
bootflash:dhcp-snooping-bindings-database
Command
set security acl ip acl_name permit dhcp-snooping
set security acl ip acl_name permit ip any any
"Enabling DHCP
OL-8978-04

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6506Catalyst 6509Catalyst 6513

Table of Contents