180 DHCP Snooping
Default Configuration
DHCP snooping on VLAN disabled.
Command Mode
Global Configuration mode.
User Guidelines
•
Prior
to enabling DHCP snooping on a VLAN, globally enable DHCP snooping.
Example
The following example enables DHCP snooping on a VLAN.
ip dhcp snooping trust
The ip dhcp snooping trust Interface Configuration mode command configures a port as trusted for
DHCP snooping purposes. Use the no form of this command to return to the default setting.
Syntax
• ip dhcp snooping trust
• no ip dhcp snooping trust
Default Configuration
The interface is untrusted.
Command Mode
Interface Configuration (Ethernet, Port-channel) mode.
User Guidelines
• Configure as trusted ports those that are connected to a DHCP server or to other switches or routers.
Configure as untrusted ports those that are connected to DHCP clients.
ip dhcp snooping information option allowed-untrusted
The ip dhcp snooping information option allowed-untrusted Global Configuration mode command
on a switch configures the switch to accept DHCP packets with option-82 information from
an untrusted port. Use the no form of this command to configure the switch to drop these packets from
an untrusted port.
console (config)#
ip dhcp snooping vlan
vlan-id
5400_CLI.book Page 180 Wednesday, December 17, 2008 4:33 PM