beautypg.com

Dhcp snooping configuration task list, Configuring basic dhcp snooping, Table 4 – H3C Technologies H3C S12500-X Series Switches User Manual

Page 78

background image

67

Table 4 Handling strategies

If a DHCP request

has…

Handling

strategy

DHCP snooping…

Option 82

Drop

Drops the message.

Keep

Forwards the message without changing Option 82.

Replace

Forwards the message after replacing the original Option 82 with
the Option 82 padded according to the configured padding format,

padding content, and code type.

No Option 82

N/A

Forwards the message after adding the Option 82 padded
according to the configured padding format, padding content, and

code type.

DHCP snooping configuration task list

If you configure DHCP snooping settings on a Layer 2 Ethernet interface that has been added to an

aggregation group, the settings do not take effect unless the interface is removed from the aggregation

group.

Tasks at a glance

(Required.)

Configuring basic DHCP snooping

(Optional.)

Configuring Option 82

(Optional.)

Saving DHCP snooping entries

(Optional.)

Enabling DHCP starvation attack protection

(Optional.)

Enabling DHCP-REQUEST attack protection

(Optional.)

Setting the maximum number of DHCP snooping entries

(Optional.)

Configuring DHCP packet rate limit

Configuring basic DHCP snooping

Follow these guidelines when you configure basic DHCP snooping:

Specify the ports connected to authorized DHCP servers as trusted ports to make sure that DHCP
clients can obtain valid IP addresses. The trusted ports and the ports connected to DHCP clients must

be in the same VLAN.

Layer 2 Ethernet interfaces and Layer 2 aggregate interfaces can be specified as trusted ports. For
more information about aggregate interfaces, see Layer 2—LAN Switching Configuration Guide.

If you configure DHCP snooping settings on a Layer 2 Ethernet interface that has been added to an
aggregation group, the settings do not take effect unless the interface is removed from the

aggregation group.

DHCP snooping can work with QinQ to record VLAN tags for DHCP packets received from clients.
For more information about QinQ, see Layer 2LAN Switching Configuration Guide.

To configure basic DHCP snooping:

This manual is related to the following products: