23-7
Cisco IE 3000 Switch Software Configuration Guide
OL-13018-03
Chapter 23 Configuring DHCP Features and IP Source Guard
Configuring DHCP Snooping
DHCP Snooping Configuration Guidelines
These are the configuration guidelines for DHCP snooping.
•
You must globally enable DHCP snooping on the switch.
•
DHCP snooping is not active until DHCP snooping is enabled on a VLAN.
•
Before globally enabling DHCP snooping on the switch, make sure that the devices acting as the
DHCP server and the DHCP relay agent are configured and enabled.
•
When you globally enable DHCP snooping on the switch, these Cisco IOS commands are not
available until snooping is disabled. If you enter these commands, the switch returns an error
message, and the configuration is not applied.
–
ip dhcp relay information check
global configuration command
–
ip dhcp relay information policy
global configuration command
–
ip dhcp relay information trust-all
global configuration command
–
ip dhcp relay information trusted
interface configuration command
•
Before configuring the DHCP snooping information option on your switch, be sure to configure the
device that is acting as the DHCP server. For example, you must specify the IP addresses that the
DHCP server can assign or exclude, or you must configure DHCP options for these devices.
•
If the DHCP relay agent is enabled but DHCP snooping is disabled, the DHCP option-82 data
insertion feature is not supported.
Table 23-1
Default DHCP Snooping Configuration
Feature
Default Setting
DHCP server
Enabled in Cisco IOS software, requires configuration
1
1.
The switch responds to DHCP requests only if it is configured as a DHCP server.
DHCP relay agent
Enabled
2
2.
The switch relays DHCP packets only if the IP address of the DHCP server is configured on the SVI of the DHCP client.
DHCP packet forwarding address
None configured
Checking the relay agent information
Enabled (invalid messages are dropped)
2
DHCP relay agent forwarding policy
Replace the existing relay agent information
2
DHCP snooping enabled globally
Disabled
DHCP snooping information option
Enabled
DHCP snooping option to accept packets on
untrusted input interfaces
3
3.
Use this feature when the switch is an aggregation switch that receives packets with option-82 information from an edge switch.
Disabled
DHCP snooping limit rate
None configured
DHCP snooping trust
Untrusted
DHCP snooping VLAN
Disabled
DHCP snooping MAC address verification
Enabled
DHCP snooping binding database agent
Enabled in Cisco IOS software, requires configuration. This feature is
operational only when a destination is configured.