dhcp-security

 

Syntax

Hierarchy Level

Release Information

Statement introduced in Junos OS Release 13.2X50-D10 for EX Series switches.

Statement introduced in Junos OS Release 13.2 for the QFX series.

Support for static-ipv6, neighbor-discovery-inspection, ipv6-source-guard, no-dhcpv6-snooping, and no-option37 introduced in Junos OS Release 13.2X51-D20 for EX Series switches.

Support for dhcpv6-options, option-16, option-18, option-37, no-dhcpv6-options, no-option16, no-option18, and no-option37 introduced in Junos OS Release 14.2 for EX Series switches.

Description

Configure DHCP or DHCPv6 snooping on the switch. DHCP snooping is also enabled automatically if you configure any of the following port security features within this hierarchy:

  • Dynamic ARP inspection (DAI)

  • IP source guard

  • DHCP option 82

  • Static IP

For switches that support DHCPv6, both DHCP snooping and DHCPv6 snooping are enabled automatically if you configure any of the afore-mentioned features or any of the following IPv6 features:

  • IPv6 neighbor discovery inspection

  • IPv6 source guard

  • Static IPv6

Note

On EX9200 switches, DHCP Snooping, DHCPv6 Snooping and Port Security features are not supported in MC-LAG scenario.

The remaining statements are explained separately.

Required Privilege Level

interface—To view this statement in the configuration.

interface-control—To add this statement to the configuration.