Configuration Guide Configuring DHCP Snooping
Working Principle
During snooping, the binding database is updated timely based on the types of DHCP packets.
 Generating Binding Entries
When a DHCP-ACK packet on a trusted port is snooped, the client's IP address, MAC address, and lease time field are
extracted together with the port ID (an wired interface index or a WLAN ID)and VLAN ID. Then, a binding entry of it is
generated.
 Deleting Binding Entries
When the recorded lease time of a binding entry is due, it will be deleted if a legal DHCP-RELEASE/DHCP-DECLINE packet
sent by the client or a DHCP-NCK packet received on a trusted port is snooped, or the clear command is used.
Related Configuration
No configuration is needed except enabling DHCP Snooping.
8.4 Configuration
Configuring basic functions
of DHCP Snooping
(Mandatory) It is used to enable DHCP Snooping.
ip dhcp snooping suppression
Enables DHCP Snooping packet
suppression.
Enables VLAN-based DHCP Snooping.
ip dhcp snooping verify mac-address
Configures DHCP Snooping source MAC
verification.
ip dhcp snooping database write-delay
Writes the DHCP Snooping binding
database to Flash periodically.
ip dhcp snooping database write-to-flash
Writes the DHCP Snooping binding
database to Flash manually.
renew ip dhcp snooping database
Imports Flash storage to the DHCP
Snooping Binding database.
Configures DHCP Snooping trusted ports.
ip dhcp snooping check-giaddr
Enables DHCP Snooping to deal with Relay
request packets..
(Optional)It is used to optimize the address assignment by DHCP servers.
ip dhcp snooping Information option
Adds Option82 functions to DHCP request
packets.