HP 6125XLG R2306-HP 6125XLG Blade Switch Layer 3 - IP Services Configuration G - Page 75

DHCP snooping configuration task list, Configuring basic DHCP snooping

Page 75 highlights

Table 4 Handling strategies If a DHCP request has... Option 82 Handling strategy Drop Keep Replace No Option 82 N/A DHCP snooping... Drops the message. Forwards the message without changing Option 82. Forwards the message after replacing the original Option 82 with the Option 82 padded according to the configured padding format, padding content, and code type. Forwards the message after adding the Option 82 padded according to the configured padding format, padding content, and code type. DHCP snooping configuration task list If you configure DHCP snooping settings on an Ethernet interface that has been added to an aggregation group, the settings do not take effect unless the interface is removed from the aggregation group. Tasks at a glance (Required.) Configuring basic DHCP snooping (Optional.) Configuring Option 82 (Optional.) Saving DHCP snooping entries (Optional.) Enabling DHCP starvation attack protection (Optional.) Enabling DHCP-REQUEST attack protection (Optional.) Configuring DHCP packet rate limit Configuring basic DHCP snooping Follow these guidelines when you configure basic DHCP snooping: • Specify the ports connected to authorized DHCP servers as trusted ports to make sure that DHCP clients can obtain valid IP addresses. The trusted ports and the ports connected to DHCP clients must be in the same VLAN. • Ethernet interfaces and aggregate interfaces can be specified as trusted ports. For more information about aggregate interfaces, see Layer 2-LAN Switching Configuration Guide. • If you configure DHCP snooping settings on an Ethernet interface that has been added to an aggregation group, the settings do not take effect unless the interface is removed from the aggregation group. • DHCP snooping can work with QinQ to record VLAN tags for DHCP packets received from clients. Upon receiving a DHCP packet that has one VLAN tag, QinQ adds an outer tag to the packet. DHCP snooping records the two VLAN tags of the packet in a DHCP snooping entry. For more information about QinQ, see Layer 2-LAN Switching Configuration Guide. To configure basic DHCP snooping: 66

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230

66
Table 4
Handling strategies
If a DHCP request
has…
Handling
strategy
DHCP snooping…
Option 82
Drop
Drops the message.
Keep
Forwards the message without changing Option 82.
Replace
Forwards the message after replacing the original Option 82 with
the Option 82 padded according to the configured padding format,
padding content, and code type.
No Option 82
N/A
Forwards the message after adding the Option 82 padded
according to the configured padding format, padding content, and
code type.
DHCP snooping configuration task list
If you configure DHCP snooping settings on an Ethernet interface that has been added to an
aggregation group, the settings do not take effect unless the interface is removed from the aggregation
group.
Tasks at a glance
(Required.)
Configuring basic DHCP snooping
(Optional.)
Configuring Option 82
(Optional.)
Saving DHCP snooping entries
(Optional.)
Enabling DHCP starvation attack protection
(Optional.)
Enabling DHCP-REQUEST attack protection
(Optional.)
Configuring DHCP packet rate limit
Configuring basic DHCP snooping
Follow these guidelines when you configure basic DHCP snooping:
Specify the ports connected to authorized DHCP servers as trusted ports to make sure that DHCP
clients can obtain valid IP addresses. The trusted ports and the ports connected to DHCP clients
must be in the same VLAN.
Ethernet interfaces and aggregate interfaces can be specified as trusted ports. For more information
about aggregate interfaces, see
Layer 2—LAN Switching Configuration Guide
.
If you configure DHCP snooping settings on an Ethernet interface that has been added to an
aggregation group, the settings do not take effect unless the interface is removed from the
aggregation group.
DHCP snooping can work with QinQ to record VLAN tags for DHCP packets received from clients.
Upon receiving a DHCP packet that has one VLAN tag, QinQ adds an outer tag to the packet.
DHCP snooping records the two VLAN tags of the packet in a DHCP snooping entry. For more
information about QinQ, see
Layer 2
LAN Switching Configuration Guide
.
To configure basic DHCP snooping: