87
{
DHCP snooping receives a DHCP packet with two VLAN tags.
For example, if the outer VLAN tag is 10 and the inner VLAN tag is 20, the VLAN ID field is
000a.0014. The hexadecimal digit
a
represents the outer VLAN tag 10, and the hexadecimal
digit
14
represents the inner VLAN tag 20.
•
The device name (
sysname
) must not include spaces if it is configured as the padding content
for sub-option 1. Otherwise, the DHCP snooping device will fail to add or replace Option 82.
To configure DHCP snooping to support Option 82:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type interface-number
N/A
3.
Enable DHCP snooping to
support Option 82.
dhcp snooping information enable
By default, DHCP snooping
does not support Option
82.
4.
(Optional.) Configure a
handling strategy for DHCP
requests that contain
Option 82.
dhcp snooping information strategy
{
drop
|
keep
|
replace
}
By default, the handling
strategy is
replace
.
5.
(Optional.) Configure the
padding mode and padding
format for the Circuit ID
sub-option.
dhcp snooping information
circuit-id
{ [
vlan
vlan-id
]
string
circuit-id
| {
normal
|
verbose
[
node-identifier
{
mac
|
sysname
|
user-defined
node-identifier
} ] } [
format
{
ascii
|
hex
} ] }
By default, the padding
mode is
normal
and the
padding format is
hex
for
the Circuit ID sub-option.
6.
(Optional.) Configure the
padding mode and padding
format for the Remote ID
sub-option.
dhcp snooping information
remote-id
{
normal
[
format
{
ascii
|
hex
} ] | [
vlan
vlan-id
]
string
remote-id
|
sysname
}
By default, the padding
mode is
normal
and the
padding format is
hex
for
the Remote ID sub-option.
Configuring DHCP snooping entry auto backup
The auto backup function saves DHCP snooping entries to a backup file, and allows the DHCP
snooping device to download the entries from the backup file at device reboot. The entries on the
DHCP snooping device cannot survive a reboot. The auto backup helps the security features provide
services if these features (such as IP source guard) must use DHCP snooping entries for user
authentication.
NOTE:
If you disable DHCP snooping with the
undo
dhcp snooping enable
command, the device deletes
all DHCP snooping entries, including those stored in the backup file.
To save DHCP snooping entries:
Step Command
Remarks
1.
Enter system view.
system-view
N/A