beautypg.com

Allied Telesis AlliedWare Plus Operating System Version 5.4.4C (x310-26FT,x310-26FP,x310-50FT,x310-50FP) User Manual

Page 1427

background image

DHCP Snooping Introduction and Configuration

Software Reference for x310 Series Switches

C613-50046-01 REV A

AlliedWare Plus

TM

Operating System - Version 5.4.4C

55.5

Operation

Figure 55-1

shows DHCP packet flow between DHCP clients and server, where:

Switch A has DHCP snooping enabled. The DHCP server is connected to a trusted port
on Switch A; DHCP clients and Switch B are connected to untrusted ports.

Switch A is configured to add and remove DHCP Relay Agent Option 82 information
(

ip dhcp snooping agent-option command on page 56.10

).

Switch A is configured to forward DHCP packets that already contain DHCP Relay
Agent Option 82 information without changing it (

ip dhcp snooping agent-option

allow-untrusted command on page 56.11

).

Switch B is Layer 2 switching traffic from downstream DHCP clients, and adds and
removes DHCP Relay Agent Option 82 information.

Figure 55-1: DHCP packet flow with DHCP snooping and DHCP Relay Agent Option 82 (agent option)

For more information about DHCP Relay Agent Option 82, see RFC 3046, DHCP Relay
Agent Information Option.

DHCP
server

DHCP clients

Switch A

Switch B

Untrusted ports

Trusted port

DHCP server: Receives DHCP requests and sends replies with IP address leases assigned based on
Option 82 info. Reply includes Option 82 info.

dhcpsn_opt82

Switch A:
Adds Option 82
info.
Forwards
DHCP request

DHCP client:
Sends DHCP
request.

Switch A:
Ignores
Option 82 info.
Forwards
DHCP request.

Switch B:
Adds
Option 82 info.
Forwards
DHCP request.

DHCP client:
Sends DHCP
request.

Switch A:
Ignores
Option 82 info.
Forwards
DHCP reply.
Records lease
entry in DHCP
snooping
database.

Switch B:
Removes
Option 82 info
Forwards
DHCP reply

DHCP client:
Receives
DHCP reply.

Switch A:
Removes
Option 82 info.
Forwards
DHCP reply.
Records lease
entry in DHCP
snooping database.

DHCP client:
Receives
DHCP reply.