Configuring dhcp snooping basic functions, Configuration guidelines, Configuration procedure – H3C Technologies H3C S12500 Series Switches User Manual

Page 91

Advertising
background image

77

If a client's

requesting message

has…

Handling

strategy

Padding format The DHCP snooping switch…

N/A private

Forwards the message after adding the Option
82 padded in private format.

N/A standard

Forwards the message after adding the Option
82 padded in standard format.

N/A verbose

Forwards the message after adding the Option
82 padded in verbose format.

N/A user-defined

Forwards the message after adding the
user-defined Option 82.

NOTE:

The handling strategy and padding format for Option 82 on the DHCP snooping device are the same as
those on the relay agent.

Configuring DHCP snooping basic functions

Configuration guidelines

Follow these guidelines when you configure DHCP snooping basic functions:

You need to specify the ports connected to the valid DHCP servers as trusted to make sure DHCP

clients can obtain valid IP addresses. The trusted port and the port connected to the DHCP client
must be in the same VLAN.

You can specify Layer 2 Ethernet interfaces and Layer 2 aggregate interfaces as trusted ports. For
more information about aggregate interfaces, see Layer 2—LAN Switching Configuration Guide.

If an Ethernet interface is added to an aggregation group, DHCP snooping configured on the
interface will not take effect. After the interface quits from the aggregation group, DHCP snooping

will be effective.

DHCP snooping can work with basic QinQ or flexible QinQ. When receiving a packet without any
VLAN tag from the DHCP client to the DHCP server, the DHCP snooping device adds a VLAN tag
to the packet. If the packet has one VLAN tag, the device adds another VLAN tag to the packet and

records the two VLAN tags in a DHCP snooping entry. The newly added VLAN tag is the outer tag.

If the packet has two VLAN tags, the device directly forwards the packet to the DHCP server without

adding any tag. If you need to add a new VLAN tag and meanwhile modify the original VLAN tag
for the packet, DHCP snooping cannot work with flexible QinQ.

Configuration procedure

To configure DHCP snooping basic functions:

Step Command

Remarks

1.

Enter system view.

system-view

N/A

2.

Enable DHCP snooping.

dhcp-snooping Disabled

by

default.

Advertising