84
Application of trusted and untrusted ports
Configure ports facing the DHCP server as trusted ports, and configure other ports as untrusted
ports.
As shown in
, configure the DHCP snooping device's port that is connected to the DHCP
server as a trusted port. The trusted port forwards response messages from the DHCP server to the
client. The untrusted port connected to the unauthorized DHCP server discards incoming DHCP
response messages.
Figure 35 Trusted and untrusted ports
In a cascaded network as shown in
, configure each DHCP snooping device's ports
connected to other DHCP snooping devices as trusted ports. To save system resources, you can
disable the untrusted ports that are not directly connected to DHCP clients from generating DHCP
snooping entries.
Figure 36 Trusted and untrusted ports in a cascaded network
DHCP snooping
Switch A
DHCP snooping
Switch C
DHCP client
Host D
DHCP client
Host C
DHCP client
Host B
DHCP server
Device
DHCP snooping
Switch B
GE1/0/4
GE1/0/2
GE1/0/3
GE1/0/1
GE1/0/2
GE1/0/3
GE1/0/4
GE1/0/2
GE1/0/1
GE1/0/3
GE1/0/1
DHCP client
Host A
GE1/0/1
Untrusted ports enabled to record snooping entries
Untrusted ports disabled from recording snooping entries
Trusted ports