Dhcp snooping configuration task list, Configuring dhcp snooping basic functions, Configuration guidelines – H3C Technologies H3C S10500 Series Switches User Manual
Page 84: Configuration procedure

73
NOTE:
The handling strategy and padding format for Option 82 on the DHCP snooping device are the same as
those on the relay agent.
DHCP snooping configuration task list
Complete the following tasks to configure DHCP snooping:
Task Remarks
Configuring DHCP snooping basic functions
Required
Configuring DHCP snooping to support Option 82
Optional
Configuring DHCP snooping entries backup
Optional
Enabling DHCP starvation attack protection
Optional
Enabling DHCP-REQUEST message attack protection
Optional
Configuring DHCP packet rate limit
Optional
Configuring DHCP snooping basic functions
Configuration guidelines
Follow these guidelines when configure DHCP snooping basic functions:
•
You must specify the ports connected to the authorized DHCP servers as trusted to ensure that DHCP
clients can obtain valid IP addresses. The trusted port and the port connected to the DHCP client
must be in the same VLAN.
•
You can specify Layer 2 Ethernet ports and Layer 2 aggregate interfaces as trusted ports. For more
information about aggregate interfaces, see the Layer 2—LAN Switching Configuration Guide.
•
If a Layer 2 Ethernet port is added to an aggregation group, the DHCP snooping configuration of
the interface will not take effect. After the interface quits the aggregation group, the configuration
will be effective.
•
DHCP snooping can work with basic QinQ or flexible QinQ. When receiving a packet without any
VLAN tag from the DHCP client to the DHCP server, the DHCP snooping device adds a VLAN tag
to the packet. If the packet has one VLAN tag, the device adds another VLAN tag to the packet and
records the two VLAN tags in a DHCP snooping entry. The newly added VLAN tag is the outer tag.
If the packet has two VLAN tags, the device directly forwards the packet to the DHCP server without
adding any tag. If you need to add a new VLAN tag and meanwhile modify the original VLAN tag
for the packet, DHCP snooping cannot work with flexible QinQ.
Configuration procedure
Follow these steps to configure DHCP snooping basic functions:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable DHCP snooping
dhcp-snooping
Required
Disabled by default.