DHCP Snooping on a Cisco Catalyst switch

The 3750 is configured with ip routing and a layer 3 interface on the subnet where the DHCP servers are located (10.0.10.0/24). VLAN 20 has been created on the 3750 with an interface ip address of 10.0.20.254/24.

All the DHCP server configuration and helper addresses were tested and working prior to implementing DHCP snooping to eliminate any doubt as to whether the DHCP snooping configuration is working or not.

So, let’s get started.

For DHCP snooping to work, you have to enable it globally. That is done with the following global configuration command:

Switch(config)#ip dhcp snooping

You also have to tell the switch which VLANs to monitor. In a production environment, this would be the client VLANs, not a transit VLAN that leads to the rest of the network.

This is done with the following command:

Switch(config)#ip dhcp snooping vlan 20

At this point DHCP snooping is configured and enabled. There are several default settings that can be modified later, but that can be dealt with after we verify things are working. Here is the basic show command to verify DHCP snooping is working (specifically the top few lines):

Switch#show ip dhcp snooping

Switch DHCP snooping is enabled
DHCP snooping is configured on following VLANs:

20
DHCP snooping is operational on following VLANs:

Insertion of option 82 is enabled
circuit-id format: vlan-mod-port

remote-id format: MAC
Option 82 on untrusted port is not allowed
Verification of hwaddr field is enabled
Verification of giaddr field is enabled
DHCP snooping trust/rate is configured on the following Interfaces:
Interface Trusted Rate limit (pps)

Once you verify DHCP snooping is working, you can verify DHCP lease information starts to populate the DHCP snooping binding table on the switch with the following command:

Switch#show ip dhcp snooping binding

AA:2C:DD:09:D1:CD 10.0.20.28 28781 dhcp-snooping 20 FastEthernet0/13
Total number of bindings: 1

If you have a DHCP server plugged into a switch with DHCP snooping enabled, or if you have a layer 2 LAN port connected to an upstream switch where the DHCP server resides, you’ll have to trust that port. To do this, enter the following command in interface configuration mode:

Switch(config-if)#ip dhcp snooping trust

In summary :
ip dhcp snooping
ip dhcp snooping vlan 20
ip dhcp snooping trust
!
show ip dhcp snooping
show ip dhcp snooping binding