3-10
To do… Use the command… Remarks
Enable IP filtering ip check source ip-address
[ mac-address ]
Required
By default, this function is
disabled.
Create an IP static binding
entry
ip source static binding
ip-address ip-address
[ mac-address mac-address ]
Optional
By default, no static binding
entry is created.
z Enable DHCP snooping and specify trusted ports on the device before configuring IP filtering.
z You are not recommended to configure IP filtering on the ports of an aggregation group.
DHCP Snooping Configuration Example

DHCP-Snooping Option 82 Support Configuration Example

Network requirements
As shown in Figure 3-6, GigabitEthernet 1/0/5 of Switch is connected to the DHCP server, and
GigabitEthernet 1/0/1, GigabitEthernet 1/0/2, and GigabitEthernet 1/0/3 are respectively connected to
Client A, Client B, and Client C.
z Enable DHCP snooping on Switch.
z Specify GigabitEthernet 1/0/5 on Switch as a trusted port for DHCP snooping.
z Enable DHCP-snooping Option 82 support on Switch and set the remote ID field in Option 82 to the
system name of Switch. Set the circuit ID sub-option to “abcd” in DHCP packets from VLAN 1 on
GigabitEthernet 1/0/3.
Figure 3-6 Network diagram for DHCP-snooping Option 82 support configuration
GE1/0/2
Client B
Switch
DHCP Snooping
Client A
GE1/0/1
Client C
GE1/0/3
GE1/0/5
DHCP Server