DHCP Snooping

DHCP Snooping

DHCP Operations

DORA: DHCP Operations Order

  1. Discover: DHCP Discover (Client, Broadcast)
  2. Offer: DHCP Offer (Server, Unicast/Broadcast)
  3. Request: DHCP Request (Client, Broadcast)
  4. Ack: DHCP Ack (Server, Unicast/Broadcast)

DHCP Server messages

  1. OFFER
    1. Initial response to a client request
  2. ACK
    1. Provisioning of IP address and DHCP information
  3. NAK
    1. Decline's a user's request for provisioning
      1. Opposite of an ACK

DHCP Client Messages

  1. DISCOVER
    1. Initial packet searching for a DHCP server
  2. REQUEST
    1. IP address/DHCP information provisioning request
  3. RELEASE
    1. Release of leased IP address
  4. DECLINE
    1. Decline offered IP address by a server

DHCP Snooping config

  1. Enable IP DHCP snooping
    2. config# ip dhcp snooping
  2. Assign a VLAN to be snooped
    1. config# ip dhcp snooping vlan <vlan ID>
  3. Disable IP DHCP snooping information
    1. config# no ip dhcp snooping information option
  4. Trust the server-facing interface
    1. config-if# ip dhcp snooping trust
  5. Check DHCP snooping table
    1. #sho ip dhcp snooping binding
  6. Configure DHCP rate limiting
    1. config-if-range# ip dhcp snooping limit rate <allowed messages per second>
  7. Configure errdisable recovery
    1. config# errdisable recovery cause dhcp-rate-limit
    2. # show errdisable recovery

Metadata

OSI or TCP/IP Layer

CCNA Exam Topic

#extop-5-7

Contributors

Sources

Configuring DHCP Snooping - Cisco Systems


  1. Source: Original ↩︎