5-3
Figure 5-2
Configure trusted ports in a cascaded network
DHCP snooping
Switch A
DHCP snooping
Switch C
DHCP client
Host D
DHCP client
Host C
DHCP client
Host B
DHCP server
DHCP snooping
Switch B
GE1/0/4
GE1/0/2
GE1/0/3
GE1/0/1
GE1/0/2
GE1/0/3
GE1/0/4
GE1/0/2
Eth1/1
GE1/0/3
GE1/0/1
DHCP client
Host A
GE1/0/1
Untrusted ports
Trusted ports disabled from recording binding entries
Trusted ports enabled to record binding entries
Table 5-1
describes roles of the ports shown in
Figure 5-2
.
Table 5-1
Roles of ports
Device
Untrusted port
Trusted port disabled from
recording binding entries
Trusted port enabled to
record binding entries
Switch A
GE1/0/1
GE1/0/3
GE1/0/2
Switch B
GE1/0/3 and GE1/0/4 GE1/0/1
GE1/0/2
Switch C
GE1/0/1
GE1/0/3 and Ethernet 1/4
GE1/0/2
DHCP Snooping Support for Option 82
Option 82 records the location information of the DHCP client. The administrator can locate the DHCP
client to further implement security control and accounting. For more information, refer to
Relay agent
option (Option 82).
If DHCP snooping supports Option 82, it will handle a client’s request according to the contents defined
in Option 82, if any. The handling strategies are described in the table below.
If a reply returned by the DHCP server contains Option 82, the DHCP snooping device will remove the
Option 82 before forwarding the reply to the client. If the reply contains no Option 82, the DHCP
snooping device forwards it directly.