22-3
Catalyst 3750 SwitchSoftware Configuration Guide
OL-8550-09
Chapter22 Configuring DHCP Features and IP Source Guard Features
Understanding DHCP Snooping
The DHCP snooping binding database has the MAC address, the IP address, the lease time, the binding
type, the VLAN number, and the interface information that corresponds to the local untrusted interfaces
of a switch. It does not have information regarding hosts interconnected with a trusted interface.
In a service-provider network, a trusted interface is connected to a port on a device in the same network.
An untrusted interface is connected to an untrusted interface in the network or to an interface on a device
that is not in the network.
When a switch receives a packet on an untrusted interface and the interface belongs to a VLAN in which
DHCP snooping is enabled, the switch compares the source MAC address and the DHCP client hardware
address. If the addresses match (the default), the switch forwards the packet. If the addresses do not
match, the switch drops the packet.
The switch drops a DHCP packet when one of these situations occurs:
A packet from a DHCP server, such as a DHCPOFFER, DHCPACK, DHCPNAK, or
DHCPLEASEQUERY packet, is received from outside the network or firewall.
A packet is received on an untrusted interface, and the source MAC address and the DHCP client
hardware address do not match.
The switch receives a DHCPRELEASE or DHCPDECLINE broadcast message that has a MAC
address in the DHCP snooping binding database, but the interface information in the binding
database does not match the interface on which the message was received.
A DHCP relay agent forwards a DHCP packet that includes a relay-agent IP address that is not
0.0.0.0, or the relay agent forwards a packet that includes option-82 information to an untrusted port.
If the switch is an aggregation switch supporting DHCP snooping and is connected to an edge switch
that is inserting DHCP option-82 information, the switch drops packets with option-82 information when
packets are received on an untrusted interface. If DHCP snooping is enabled and packets are received on
a trusted port, the aggregation switch does not learn the DHCP snooping bindings for connected devices
and cannot build a complete DHCP snooping binding database.
When option-82 information is inserted by an edge switch in software releases earlier than Cisco IOS
Release 12.2(25)SEA, you cannot configure DHCP snooping on an aggregation switch because the
DHCP snooping bindings database is not properly populated. You also cannot configure IP source guard
and dynamic Address Resolution Protocol (ARP) inspection on the switch unless you use static bindings
or ARP access control lists (ACLs).
When an aggregation switch can be connected to an edge switch through an untrusted interface and you
enter the ip dhcp snooping information option allow-untrusted global configuration command, the
aggregation switch accepts packets with option-82 information from the edge switch. The aggregation
switch learns the bindings for hosts connected through an untrusted switch interface. The DHCP security
features, such as dynamic ARP inspection or IP source guard, can still be enabled on the aggregation
switch while the switch receives packets with option-82 information on untrusted input interfaces to
which hosts are connected. The port on the edge switch that connects to the aggregation switch must be
configured as a trusted interface.