283
Table 110 Roles of ports
Device Untrusted port
Trusted port disabled from
recordin
Trusted port enabled to
record bindin
Switch A GigabitEthernet 1/0/1 GigabitEthernet 1/0/3 GigabitEthernet 1/0/2
Switch B
GigabitEthernet 1/0/3 and
GigabitEthernet 1/0/4
GigabitEthernet 1/0/1 GigabitEthernet 1/0/2
Switch C GigabitEthernet 1/0/1
GigabitEthernet 1/0/3 and
GigabitEthernet 1/0/4
GigabitEthernet 1/0/2
DHCP snooping support for Option 82
Option 82 records the location information of the DHCP client. The administrator can locate the DHCP
client to further implement security control and accounting. For more information, see the chapter “DHCP
overview.”
If DHCP snooping supports Option 82, it will handle a client’s request according to the contents defined
in Option 82, if any. The handling strategies are described in the table below.
If a reply returned by the DHCP server contains Option 82, the DHCP snooping device will remove the
Option 82 before forwarding the reply to the client. If the reply contains no Option 82, the DHCP
snooping device forwards it directly.
If a client’s requesting
messa
The DHCP snooping device will…
Option 82
Drop Drop the message.
Keep Forward the message without changing Option 82.
Replace
Forward the message after replacing the original Option 82
with the Option 82 padded in normal format.
no Option 82 —
Forward the message after adding the Option 82 padded in
normal format.
DHCP snooping configuration task list
Complete the following tasks to configure DHCP snooping:
Task Remarks
Enabling DHCP snooping
Required
By default, DHCP snooping is disabled.
Configuring DHCP snooping
functions on an interface
Required
Specify an interface as trusted and configure DHCP snooping to support
Option 82.
By default, an interface is untrusted and DHCP snooping does not support
Option 82.
IMPORTANT:
You need to specify the ports connected to the authorized DHCP servers as
trusted to ensure that DHCP clients can obtain valid IP addresses. The trusted
port and the port connected to the DHCP client must be in the same VLAN.