Users Guide

Table Of Contents
NOTE: If you move a DHCP client from an untrusted port to another untrusted port within the VLAN, the DHCP snooping
binding database is not updated. The switch drops subsequent packets from the host. However, if you move a DHCP client from
an untrusted port to a trusted port, there is no impact to the trac from the host.
Restrictions for DHCP snooping
DHCP snooping is not supported for the management VLAN.
DHCP snooping is not supported with VxLAN bridges.
The maximum number of supported DHCP snooping binding entries is 4000.
OS10 does not support multi-hop DHCP snooping.
Rouge DHCP server detection
In the following topology, a trusted DHCP server, a DHCP client, and a rouge DHCP server are connected to the DHCP snooping switch.
The DHCP client and DHCP server are on the same VLAN. The physical port eth 1/1/2 is a trusted port. When the rouge DHCP server
sends a DHCP packet to the client, the switch analyzes the packet. As the rouge server is connected to the switch to an untrusted eth
1/1/3 interface the switch deems the server as a rouge DHCP server and drops the packet.
DHCP snooping with DHCP relay
In the following topology, the DHCP snooping switch is a the DHCP relay agent for DHCP clients on VLAN 100. The DHCP server is
reachable on VLAN 200 through eth 1/1/2. The switch forwards client DHCP messages to the trusted DHCP server. The switch processes
DHCP packets from the DHCP server before forwarding them to DHCP clients. As the rouge server is connected to the switch to the eth
1/1/3 interface which is an untrusted port, the switch drops the packet.
System management
169