
Chapter 8
| General Security Measures
DHCPv4 Snooping
– 284 –
compatible DHCP servers to use the information when assigning IP addresses,
or to set other services or policies for clients.
◆
When the DHCP Snooping Information Option 82 is enabled, the requesting
client (or an intermediate relay agent that has used the information fields to
describe itself ) can be identified in the DHCP request packets forwarded by the
switch and in reply packets sent back from the DHCP server.
◆
When the DHCP Snooping Information Option is enabled, clients can be
identified by the switch port to which they are connected rather than just their
MAC address. DHCP client-server exchange messages are then forwarded
directly between the server and client without having to flood them to the
entire VLAN.
◆
DHCP snooping must be enabled for the DHCP Option 82 information to be
inserted into packets. When enabled, the switch will only add/remove option
82 information in incoming DHCP packets but not relay them. Packets are
processed as follows:
■
If an incoming packet is a DHCP request packet with option 82 information,
it will modify the option 82 information according to settings specified with
ip dhcp snooping information policy
command.
■
If an incoming packet is a DHCP request packet without option 82
information, enabling the DHCP snooping information option will add
option 82 information to the packet.
■
If an incoming packet is a DHCP reply packet with option 82 information,
enabling the DHCP snooping information option will remove option 82
information from the packet.
Example
This example enables the DHCP Snooping Information Option.
Console(config)#ip dhcp snooping information option
Console(config)#
ip dhcp snooping
information option
encode no-subtype
This command disables the use of sub-type and sub-length fields for the
circuit-ID (CID) and remote-ID (RID) in Option 82 information generated by the
switch. Use the
no
form to enable the use of these fields.
Syntax
[
no
]
ip dhcp snooping information option encode no-subtype
Default Setting
Enabled
Command Mode
Global Configuration
Summary of Contents for AS5700-54X
Page 42: ...Contents 42...
Page 44: ...Figures 44...
Page 52: ...Tables 52...
Page 54: ...Section I Getting Started 54...
Page 80: ...Chapter 1 Initial Switch Configuration Setting the System Clock 80...
Page 210: ...Chapter 6 Remote Monitoring Commands 210...
Page 358: ...Chapter 9 Access Control Lists ACL Information 358...
Page 418: ...Chapter 12 Port Mirroring Commands RSPAN Mirroring Commands 418...
Page 436: ...Chapter 15 UniDirectional Link Detection Commands 436...
Page 442: ...Chapter 16 Address Table Commands 442...
Page 506: ...Chapter 18 VLAN Commands Configuring VXLAN Tunneling 506...
Page 526: ...Chapter 19 Class of Service Commands Priority Commands Layer 3 and 4 526...
Page 544: ...Chapter 20 Quality of Service Commands 544...
Page 652: ...Chapter 22 Multicast Filtering Commands MLD Proxy Routing 652...
Page 680: ...Chapter 23 LLDP Commands 680...
Page 722: ...Chapter 24 CFM Commands Delay Measure Operations 722...
Page 732: ...Chapter 25 Domain Name Service Commands 732...
Page 790: ...Chapter 27 IP Interface Commands ND Snooping 790...
Page 1072: ...Section III Appendices 1072...
Page 1102: ...List of CLI Commands 1102...
Page 1115: ......
Page 1116: ...AS5700 54X AS6700 32X E032016 ST R02 149100000198A...