General Security Measures
4-149
4
• When the DHCP Snooping Information Option is enabled, the requesting
client (or an intermediate relay agent that has used the information fields to
describe itself) can be identified in the DHCP request packets forwarded by
the switch and in reply packets sent back from the DHCP server, by the switch
port to which they are connected rather than just their MAC address. DHCP
client-server exchange messages are then forwarded directly between the
server and client without having to flood them to the entire VLAN.
• DHCP snooping must be enabled on the switch for the DHCP Option 82
information to be inserted into packets.
• Use the
ip dhcp snooping information option
command (page 4-148) to
specify how to handle DHCP client request packets which already contain
Option 82 information.
Example
This example enables the DHCP Snooping Information Option.
ip dhcp snooping information policy
This command sets the DHCP snooping information option policy for DHCP client
packets that include Option 82 information.
Syntax
ip dhcp snooping information policy
{
drop
|
keep
|
replace
}
•
drop
- Drops the client’s request packet instead of relaying it.
•
keep
- Retains the Option 82 information in the client request, and forwards
the packets to trusted ports.
•
replace
- Replaces the Option 82 information in the client’s request with
information about the relay agent itself, inserts the relay agent’s address
(when DHCP snooping is enabled), and forwards the packets to trusted
ports.
Default Setting
replace
Command Mode
Global Configuration
Command Usage
When the switch receives DHCP packets from clients that already include
DHCP Option 82 information, the switch can be configured to set the action
policy for these packets. The switch can drop the DHCP packets, keep the
existing information, or replace it with the switch’s relay information.
Example
Console(config)#ip dhcp snooping information option
Console(config)#
Console(config)#ip dhcp snooping information policy drop
Console(config)#
Summary of Contents for DG-GS1550
Page 24: ...Tables xxx ...
Page 46: ...Initial Configuration 2 10 2 ...
Page 642: ...Command Line Interface 4 342 4 ...
Page 664: ...Index 8 Index ...
Page 665: ......