Networking-Blog

My WordPress Blog

DHCP Snooping on a Cisco Catalyst switch

The 3750 is configured with ip routing and a layer 3 interface on the subnet where the DHCP servers are located (10.0.10.0/24). VLAN 20 has been created on the 3750 with an interface ip address of 10.0.20.254/24.

All the DHCP server configuration and helper addresses were tested and working prior to implementing DHCP snooping to eliminate any doubt as to whether the DHCP snooping configuration is working or not.

So, let’s get started.

For DHCP snooping to work, you have to enable it globally. That is done with the following global configuration command:

Switch(config)#ip dhcp snooping

You also have to tell the switch which VLANs to monitor. In a production environment, this would be the client VLANs, not a transit VLAN that leads to the rest of the network.

This is done with the following command:

Switch(config)#ip dhcp snooping vlan 20

At this point DHCP snooping is configured and enabled. There are several default settings that can be modified later, but that can be dealt with after we verify things are working. Here is the basic show command to verify DHCP snooping is working (specifically the top few lines):

Switch#show ip dhcp snooping

Switch DHCP snooping is enabled
DHCP snooping is configured on following VLANs:

20
DHCP snooping is operational on following VLANs:

Insertion of option 82 is enabled
circuit-id format: vlan-mod-port

remote-id format: MAC
Option 82 on untrusted port is not allowed
Verification of hwaddr field is enabled
Verification of giaddr field is enabled
DHCP snooping trust/rate is configured on the following Interfaces:
Interface Trusted Rate limit (pps)

Once you verify DHCP snooping is working, you can verify DHCP lease information starts to populate the DHCP snooping binding table on the switch with the following command:

Switch#show ip dhcp snooping binding

AA:2C:DD:09:D1:CD 10.0.20.28 28781 dhcp-snooping 20 FastEthernet0/13
Total number of bindings: 1

If you have a DHCP server plugged into a switch with DHCP snooping enabled, or if you have a layer 2 LAN port connected to an upstream switch where the DHCP server resides, you’ll have to trust that port. To do this, enter the following command in interface configuration mode:

Switch(config-if)#ip dhcp snooping trust

In summary :
ip dhcp snooping
ip dhcp snooping vlan 20
ip dhcp snooping trust
!
show ip dhcp snooping
show ip dhcp snooping binding

Cisco DHCP Binding

Permanent IP-address Mapping to a host MAC-address

ip dhcp pool “ name ”
host 192.168.4.8 255.255.255.240
client-identifier 0100.24b2.7fef.e7
client-name Comms-Networks
!
ip dhcp pool “ name ”
host 192.168.4.9 255.255.255.240
client-identifier 0100.1641.6CB3.26
client-name Comms-Networks

where 01 represents the Ethernet media type. Every request sent from a DHCP client to DHCP servers
contains a hardware type and a client hardware address. For Ethernet and 802.11 wireless clients, the
hardware type is always 01.

Some HP network printers/printservers (ethernet!) prepend 00 instead of 01. Some don’t
prepend anything so only hardware-address is working with them.

The client hardware address is simply the MAC address of the client’s network
(Ethernet or Wireless) interface. Every request sent from a DHCP client to DHCP servers may optionally
also contain a DHCP Client Identifier option.

 

debug;

ip dhcp server events
debug ip dhcp server packet

 

 

 

Cisco DHCP

Cisco Dhcp Configuration :

ip dhcp excluded-address 10.10.10.250 10.10.10.254
!
ip dhcp pool DATA
   import all
   network 10.10.10.0 255.255.255.0
   default-router 10.10.10.254
   domain-name comms.co.uk
   dns-server 10.10.10.50 10.10.10.51 10.10.10.52
   netbios-name-server 10.10.10.50 10.10.10.51 10.10.10.52
   lease 0 2
   update arp