Dell OS10 DHCP Relay and Snooping Configuration - 夜莺博客

Dell OS10 DHCP Relay and Snooping Configuration

Dell's PowerSwitch OS10 splits what used to be a single DHCP feature into two independent ones: relay (how client requests reach a server in another subnet) and snooping (how the switch builds a trusted binding table so ARP inspection and IP source guard have something to work from). Both are commonly needed on the same access switch, and both map onto OS10 commands that behave differently from the older OS9 syntax. This guide covers the ip helper-address relay configuration, the global and per-VLAN snooping setup, and the trust-port model that must be correct before any of the security features will work.

DHCP Relay with ip helper-address

The DHCP server is only reachable on a Layer 3 interface. In OS10 the relay is configured on the client-facing SVI or routed port, pointing at the server address. Note the parameter order — unlike OS9, the VRF is optional and comes last.

OS10# configure terminal
OS10(config)# interface ethernet 1/1/22
OS10(conf-if-eth1/1/22)# no switchport
OS10(conf-if-eth1/1/22)# ip address 10.10.20.1/24
OS10(conf-if-eth1/1/22)# ip helper-address 20.1.1.1 vrf blue

Exactly one rule matters operationally: the client-facing and server-facing interfaces must be in the same VRF. If the helper address is in the default VRF while the SVI sits in blue, the packet is dropped and the client simply times out with no error on the switch.

Repeat the command once per server address if you run redundant DHCP servers. Unlike OS9 there is no ip dhcp relay secondary-subnet or information-option keyword to carry over — those OS9 forms have no OS10 equivalent.

Enabling DHCP Snooping

Snooping is disabled by default. Enable it globally, then scope it to the VLANs that carry clients.

OS10(config)# ip dhcp snooping
OS10(config)# ip dhcp snooping vlan 10,20

The moment it is enabled the switch starts inspecting every DHCP transaction in those VLANs and populating the binding table. Turning snooping off removes the binding table and the Dynamic ARP Inspection and Source Address Validation entries that depended on it, so plan the change accordingly.

Trust Ports

Snooping drops server-sourced offers that arrive on an untrusted port. That is the whole point, but it means the uplink toward the real DHCP server must be explicitly trusted.

OS10(config)# interface ethernet 1/1/49
OS10(conf-if-eth1/1/49)# ip dhcp snooping trust

A useful rule of thumb: trust only ports that point at another switch or at the DHCP server. Every host-facing access port stays untrusted.

Two optional hardening knobs belong in the same conversation. ip dhcp snooping verify mac-address drops frames whose source MAC does not match the client hardware address in the DHCP payload, which defeats DHCP starvation built on forged MACs. ip dhcp snooping binding lets you add static entries for hosts that are configured manually.

Verification

OS10# show ip dhcp snooping binding
OS10# show ip dhcp snooping
OS10# show ip arp inspection statistics
OS10# show running-configuration | grep -i dhcp

An empty binding table after enabling snooping almost always means one of two things: no client has completed a full DORA exchange yet in that VLAN, or the offer is being dropped because the uplink was never trusted.

Relay and Snooping Together

When the same switch both relays and snoops, the ordering is worth remembering: snooping inspects the client request before it is relayed, and the relay forwards it to the server. The reply comes back through the switch on the trusted uplink and is then written into the binding table. If you are also running VLT, check show vlt mismatch to confirm the snooping and relay configuration is symmetrical on both peers — an asymmetric relay configuration is a classic source of intermittent client failures during failover.

Related reading on this site: our Cisco IP Helper-Address: DHCP Relay Configuration relay walk-through and the Cisco DHCP Snooping: Trusted and Untrusted Ports security deployment notes. If your relays cross VRFs, the interface model in Dell OS10 VRF Configuration and Verification Guide explains why the helper address has to live in the same routing table as the client SVI.

原文链接:https://www.dell.com/support/manuals/en-gh/dell-emc-smartfabric-os10/smartfabric-os-user-guide-10-5-2-6/ip-helper-address