18-4
Catalyst 3560 Switch Software Configuration Guide
78-16156-01
Chapter 18 Configuring DHCP Features
Configuring DHCP Features
Enabling DHCP Snooping and Option 82
Beginning in privileged EXEC mode, follow these steps to enable DHCP snooping on the switch.
To disable DHCP snooping, use the no ip dhcp snooping global configuration command. To disable
DHCP snooping on a VLAN or range of VLANs, use the no ip dhcp snooping vlan vlan-id global
configuration command. To disable the insertion and removal of the option-82 field, use the no ip dhcp
snooping information option global configuration command.
This example shows how to enable DHCP snooping globally and on VLAN 10 and to configure a rate
limit of 100 packets per second on a port:
Switch(config)# ip dhcp snooping
Switch(config)# ip dhcp snooping vlan 10
Switch(config)# ip dhcp snooping information option
Switch(config)# interface gigabitethernet0/1
Switch(config-if)# ip dhcp snooping limit rate 100
Command
Purpose
Step 1
configure terminal
Enter global configuration mode.
Step 2
ip dhcp snooping
Enable DHCP snooping globally.
Step 3
ip dhcp snooping vlan vlan-id [vlan-id] Enable DHCP snooping on a VLAN or range of VLANs. You can specify
a single VLAN identified by VLAN ID number or start and end
VLAN IDs to specify a range of VLANs. The range is 1 to 4094.
Step 4
ip dhcp snooping information option
Enable the switch to insert and remove DHCP relay information
(option-82 field) in forwarded DHCP request messages to the DHCP
server.
The default is enabled.
Step 5
interface interface-id
Enter interface configuration mode, and specify the interface to be
configured.
Step 6
ip dhcp snooping trust
(Optional) Configure the interface as trusted or untrusted. You can use the
no keyword to configure an interface to receive messages from an
untrusted client. The default is untrusted.
Step 7
ip dhcp snooping limit rate rate
(Optional) Configure the number of DHCP packets per second than an
interface can receive. The range is 1 to 4294967294. The default is no rate
limit configured.
Note
We recommend an untrusted rate limit of not more than 100
packets per second. Normally, the rate limit applies to untrusted
interfaces. If you configure rate limiting for trusted interfaces,
you will need to adjust the rate limit to a higher value because
trusted interfaces might aggregate DHCP traffic in the switch.
Step 8
end
Return to privileged EXEC mode.
Step 9
show running-config
Verify your entries.
Step 10
copy running-config startup-config
(Optional) Save your entries in the configuration file.