вторник, 21 июня 2016 г.

Cisco DHCP snooping грабельки

В мемориззз,

при настройке DHCP snooping отключать передачу информационных опций:
ip dhcp snooping vlan 111-112
ip dhcp snooping
ip dhcp-server 192.168.111.100
ip dhcp-server 192.168.112.100
no ip dhcp snooping verify mac-address # не обязательно отключать
no ip dhcp snooping information option # отключать!!!

interface GigabitEthernet0/1
 switchport trunk native vlan 2
 switchport mode trunk
 ip dhcp snooping trust

sh ip dhcp snooping
Switch DHCP snooping is enabled
DHCP snooping is configured on following VLANs:
111-112
DHCP snooping is operational on following VLANs:
111-112
DHCP snooping is configured on the following L3 Interfaces:

Insertion of option 82 is disabled
   circuit-id default format: vlan-mod-port
   remote-id: 0008.30xx.xxxx (MAC)
Option 82 on untrusted port is not allowed
Verification of hwaddr field is disabled
Verification of giaddr field is enabled
DHCP snooping trust/rate is configured on the following Interfaces:

Interface                  Trusted    Allow option    Rate limit (pps)
-----------------------    -------    ------------    ----------------
GigabitEthernet0/1         yes        yes             unlimited
  Custom circuit-ids: