85
DHCP snooping support for Option 82
Option 82 records the location information about the DHCP client so the administrator can locate the
DHCP client for security and accounting purposes. For more information about Option 82, see
"
Relay agent option (Option 82)
DHCP snooping uses the same strategies as the DHCP relay agent to handle Option 82 for DHCP
request messages, as shown in
. If a response returned by the DHCP server contains Option
82, DHCP snooping removes Option 82 before forwarding the response to the client. If the response
contains no Option 82, DHCP snooping forwards it directly.
Table 5 Handling strategies
If a DHCP request
has…
Handling
strategy
DHCP snooping…
Option 82
Drop
Drops the message.
Keep
Forwards the message without changing Option 82.
Replace
Forwards the message after replacing the original Option 82 with
the Option 82 padded according to the configured padding format,
padding content, and code type.
No Option 82
N/A
Forwards the message after adding the Option 82 padded
according to the configured padding format, padding content, and
code type.
Command and hardware compatibility
Commands and descriptions for centralized devices apply to the following routers:
•
MSR1002-4/1003-8S.
•
MSR2003.
•
MSR2004-24/2004-48.
•
MSR3012/3024/3044/3064.
•
MSR954(JH296A/JH297A/JH298A/JH299A)
Commands and descriptions for distributed devices apply to MSR4060 and MSR4080 routers.
DHCP snooping configuration task list
The DHCP snooping configuration does not take effect on a Layer 2 Ethernet interface that is an
aggregation member port. The configuration takes effect when the interface leaves the aggregation
group.
Tasks at a glance
(Required.)
Configuring basic DHCP snooping
(Optional.)
(Optional.)
Configuring DHCP snooping entry auto backup
(Optional.)
Enabling DHCP starvation attack protection
(Optional.)
Enabling DHCP-REQUEST attack protection
(Optional.)
Setting the maximum number of DHCP snooping entries