Chapter 9
| General Security Measures
DHCPv4 Snooping
– 278 –
ip dhcp snooping
information option
encode no-subtype
This command disables the use of sub-type and sub-length fields for the
circuit-ID (CID) and remote-ID (RID) in Option 82 information generated by the
switch. Use the
no
form to enable the use of these fields.
Syntax
[
no
]
ip dhcp snooping information option encode no-subtype
Default Setting
Enabled
Command Mode
Global Configuration
Command Usage
◆
Option 82 information generated by the switch is based on TR-101 syntax
as shown below:
The circuit identifier used by this switch starts at sub-option1 and goes to the
end of the R-124 string. The R-124 string includes the following information:
■
sub-type - Distinguishes different types of circuit IDs.
■
sub-length - Length of the circuit ID type
■
access node identifier - ASCII string. Default is the MAC address of the
switch’s CPU. This field is set by the
ip dhcp snooping information option
command,
■
eth - The second field is the fixed string “eth”
■
slot - The slot represents the stack unit for this system.
■
port - The port which received the DHCP request. If the packet arrives over
a trunk, the value is the ifIndex of the trunk.
■
vlan - Tag of the VLAN which received the DHCP request.
Note that the sub-type and sub-length fields can be enabled or disabled
using the
ip dhcp snooping information option
command.
■
The
ip dhcp snooping information option circuit-id
command can be
used to modify the default settings described above.
◆
The format for TR101 option 82 is: “<IP> eth <SID>/<PORT>[:<VLAN>]”.
Note that the SID (Switch ID) is always 0. By default the PVID is added to
the end of the TR101 field for untagged packets. For tagged packets, the
VLAN ID is always added.
Table 55: Option 82 information
82
3-69
1
1-67
x1
x2
x3
x4
x5
x63
opt82
opt-len
sub-opt1 string-len
R-124 string