Chapter 23 DHCP Snooping
GS1350 Series User’s Guide
185
C
HAPTER
23
DHCP Snooping
23.1 Overview
With DHCP snooping, the Switch can build the binding table dynamically by snooping DHCP packets
(dynamic bindings) and filter unauthorized DHCP packets in your network.
The Switch uses a binding table to distinguish between authorized and unauthorized DHCP packets in
your network. A binding contains these key attributes:
• MAC address
• VLAN ID
• IP address
• Port number
When the Switch receives a DHCP packet, it looks up the appropriate MAC address, VLAN ID, IP
address, and port number in the binding table. If there is a binding, the Switch forwards the packet. If
there is not a binding, the Switch discards the packet.
23.1.1 What You Can Do
• Use the
DHCP Snooping
screen (
) to look at various statistics about the DHCP
snooping database.
• Use this
DHCP Snooping Configure
screen (
) to enable DHCP snooping on
the Switch (not on specific VLAN), specify the VLAN where the default DHCP server is located, and
configure the DHCP snooping database.
• Use the
DHCP Snooping Port Configure
screen (
) to specify whether ports
are trusted or untrusted ports for DHCP snooping.
• Use the
DHCP Snooping VLAN Configure
) to enable DHCP
snooping on each VLAN and to specify whether or not the Switch adds DHCP relay agent option 82
information to DHCP requests that the Switch relays to a DHCP server for each VLAN.
• Use the
DHCP Snooping VLAN Port Configure
screen (
) to apply a different
DHCP option 82 profile to certain ports in a VLAN.
23.2 DHCP Snooping
Use this screen to look at various statistics about the DHCP snooping database. To open this screen, click
Advanced Application
>
DHCP Snooping
.