C
LIENT
S
ECURITY
7-10
Additional considerations when the switch itself is a DHCP client – The port(s)
through which the switch submits a client request to the DHCP server
must be configured as trusted. Note that the switch will not add a
dynamic entry for itself to the binding table when it receives an ACK
message from a DHCP server. Also, when the switch sends out DHCP
client packets for itself, no filtering takes place. However, when the
switch receives any messages from a DHCP server, any packets received
from untrusted ports are dropped.
Command Attributes
DHCP Snooping Status – Enables DHCP snooping globally.
(Default: Disabled)
DHCP Snooping VLAN Status – Enables DHCP snooping on the
specified VLAN. (Default: Disabled)
- When DHCP snooping enabled globally on the switch, and enable d
on a VLAN, DHCP packet filtering will be performed on any
untrusted ports within the VLAN.
- When the DHCP snooping is globally disabled, DHCP snooping can
still be configured for specific VLANs, but the changes will not take
effect until DHCP snooping is globally re-enabled.
- When DHCP snooping is globally enabled, and DHCP snooping is
then disabled on a VLAN, all dynamic bindings learned for this
VLAN are removed from the binding table.
DHCP Snooping Verify MAC Address – Verifies the client’s
hardware address stored in the DHCP packet against the source MAC
address in the Ethernet header. If MAC address v erification is enabled,
and the source MAC address in the Ethernet header of the packet is not
same as the client’s hardware address in the DHCP packet, the packet is
dropped. (Default: Enabled)
DHCP Snooping Database Write to Flash – Writes all dynamically
learned snooping entries to flash memory. These entries will be restored
to the snooping table when the switch is reset. However, note that the
lease time shown for a dynamic entry that has been restored from flash
memory will no longer be valid.