05-13-2013 06:02 AM - edited 03-07-2019 01:19 PM
Helo,
I'm just conencted to a switch and it has DHCP snooping, which I've configured before, here is the config:
ip dhcp snooping vlan 1
no ip dhcp snooping information option
no ip dhcp snooping verify mac
ip dhcp snooping
What I dont understand it what the command "no ip dhcp snooping verify mac" is on there for?
Why woul we use this?
Thanks
05-13-2013 06:10 AM
Hi,
Form the config guide:
You can enable or disable DHCP snooping MAC address verification. If the device receives a packet on an untrusted interface and the source MAC address and the DHCP client hardware address do not match, address verification causes the device to drop the packet.
HTH
05-13-2013 06:19 AM
What is the default?
05-13-2013 06:22 AM
By default, it is enabled.
so,
no ip dhcp snooping verify mac
will disable it.
HTH
05-13-2013 06:24 AM
So having it turned off what verification is it doing, it seems to me it's as if it is turned off with that command as it isn't verifying the source mac address against the DHCP snooping database?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide