395
Configuring DHCP
Information About Configuring DHCP
DHCP Snooping Configuration Guidelines
You must globally enable DHCP snooping on the switch.
DHCP snooping is not active until DHCP snooping is enabled on a VLAN.
Before globally enabling DHCP snooping on the switch, make sure that the devices acting as the DHCP server and
the DHCP relay agent are configured and enabled.
Before configuring the DHCP snooping information option on your switch, be sure to configure the device that is
acting as the DHCP server. For example, you must specify the IP addresses that the DHCP server can assign or
exclude, or you must configure DHCP options for these devices.
When configuring a large number of circuit IDs on a switch, consider the impact of lengthy character serstrings on
the NVRAM or the flash memory. If the circuit-ID configurations, combined with other data, exceed the capacity of
the NVRAM or the flash memory, an error message appears.
Before configuring the DHCP relay agent on your switch, make sure to configure the device that is acting as the DHCP
server. For example, you must specify the IP addresses that the DHCP server can assign or exclude, configure DHCP
options for devices, or set up the DHCP database agent.
If the DHCP relay agent is enabled but DHCP snooping is disabled, the DHCP option-82 data insertion feature is not
supported.
If a switch port is connected to a DHCP server, configure a port as trusted by entering the
ip dhcp snooping trust
interface configuration command.
If a switch port is connected to a DHCP client, configure a port as untrusted by entering the
no ip dhcp snooping
trust
interface configuration command.
Do not enter the
ip dhcp snooping information option allow-untrusted
command on an aggregation switch to
which an untrusted device is connected. If you enter this command, an untrusted device might spoof the option-82
information.
You can display DHCP snooping statistics by entering the
show ip dhcp snooping statistics
user EXEC command,
and you can clear the snooping statistics counters by entering the
clear ip dhcp snooping statistics
privileged EXEC
command.
DHCP snooping trust
Untrusted
DHCP snooping VLAN
Disabled
DHCP snooping MAC address verification
Enabled
Cisco IOS DHCP server binding database
Enabled in Cisco IOS software, requires configuration.
Note:
The switch gets network addresses and configuration parameters
only from a device configured as a DHCP server.
DHCP snooping binding database agent
Enabled in Cisco IOS software, requires configuration. This feature is
operational only when a destination is configured.
1.
The switch responds to DHCP requests only if it is configured as a DHCP server.
2.
The switch relays DHCP packets only if the IP address of the DHCP server is configured on the SVI of the DHCP client.
3.
Use this feature when the switch is an aggregation switch that receives packets with option-82 information from an edge
switch.
Table 46
Default DHCP Snooping Settings (continued)
Feature
Default Setting
Содержание IE 4000
Страница 12: ...8 Configuration Overview Default Settings After Initial Switch Configuration ...
Страница 52: ...48 Configuring Interfaces Monitoring and Maintaining the Interfaces ...
Страница 108: ...104 Configuring Switch Clusters Additional References ...
Страница 128: ...124 Performing Switch Administration Additional References ...
Страница 130: ...126 Configuring PTP ...
Страница 140: ...136 Configuring CIP Additional References ...
Страница 146: ...142 Configuring SDM Templates Configuration Examples for Configuring SDM Templates ...
Страница 192: ...188 Configuring Switch Based Authentication Additional References ...
Страница 244: ...240 Configuring IEEE 802 1x Port Based Authentication Additional References ...
Страница 274: ...270 Configuring SGT Exchange Protocol over TCP SXP and Layer 3 Transport Configuring Cisco TrustSec Caching ...
Страница 298: ...294 Configuring VLANs Additional References ...
Страница 336: ...332 Configuring STP Additional References ...
Страница 408: ...404 Configuring DHCP Additional References ...
Страница 450: ...446 Configuring IGMP Snooping and MVR Additional References ...
Страница 490: ...486 Configuring SPAN and RSPAN Additional References ...
Страница 502: ...498 Configuring Layer 2 NAT ...
Страница 559: ...555 Configuring Network Security with ACLs How to Configure Network Security with ACLs Creating a Numbered Extended ACL ...
Страница 770: ...766 Configuring IPv6 MLD Snooping Related Documents ...
Страница 930: ...926 Configuring IP Unicast Routing Related Documents ...
Страница 956: ...952 Configuring IPv6 Unicast Routing Configuring IPv6 network 2010 AB8 2 48 network 2010 AB8 3 48 exit address family ...
Страница 976: ...972 Configuring Cisco IOS IP SLAs Operations Additional References ...
Страница 978: ...974 Dying Gasp ...
Страница 990: ...986 Configuring Enhanced Object Tracking Monitoring Enhanced Object Tracking ...
Страница 994: ...990 Configuring MODBUS TCP Displaying MODBUS TCP Information ...
Страница 996: ...992 Ethernet CFM ...
Страница 1030: ...1026 Working with the Cisco IOS File System Configuration Files and Software Images Working with Software Images ...
Страница 1066: ...1062 Using an SD Card SD Card Alarms ...