Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

DHCP

Learn about DHCP configurations on the ACX7000 Router Series. The ACX7000 Router Series include ACX7020, ACX7024, ACX7024X, ACX7100, ACX7332, ACX7348, and ACX7509 routers.

The Dynamic Host Configuration Protocol (DHCP) automatically assigns IP addresses and related settings to devices on a network. DHCP relay forwards DHCP messages between clients on one subnet and a DHCP server on another subnet. For more information about DHCP, see DHCP User Guide.

DHCP Relay

The following sample DHCP relay configuration defines a DHCP server group, binds a DHCP relay group to the server group, and adds client-facing interfaces to the DHCP relay group:

Additionally, you can enable the following DHCP relay configurations at the [edit forwarding-options dhcp-relay group group-name] hierarchy level:

  • overrides allow-snooped-clients—Enable DHCP snooping support for the relay group.
  • forward-snooped-clients configured-interfaces—Forward snooped packets only on interfaces that belong to the configured group.
    • If you want snooped packets to be handled on all interfaces, use the set forwarding-options dhcp-relay forward-snooped-clients all-interfaces command.
    • If you want snooped packets to be handled only on interfaces not in the relay group, use the set forwarding-options dhcp-relay forward-snooped-clients non-configured-interfaces command.
  • relay-option-82 circuit-id use-interface-description—Insert interface description information into DHCP Option 82, if required.

DHCP Relay No-Snoop (optional)

The DHCP relay no-snoop feature enhances network performance by preventing the DHCP relay agent from processing unicast packets related to DHCP lease renewals at the CPU level. Use dynamic firewall filters to handle DHCP traffic at the hardware level, thereby reducing CPU load significantly and optimizing system performance.

Use this command to enable the DHCP relay no-snoop feature::

For more information, see Understanding DHCP Relay No-Snoop.

Verify DHCP Relay

Use the following commands to verify the DHCP relay configuration:

  • show configuration forwarding-options dhcp-relay—Confirm the committed relay and snooping settings.
  • show forwarding-options dhcp-relay statistics—Verify relay activity and packet handling.
  • show dhcp relay statistics—Verify relay activity and packet handling.

DHCP Relay Filtering Limitations on ACX7000 Routers

You enable DHCP relay filtering using global hardware filters rather than using per-virtual routing and forwarding (VRF) filter instances. As a result, a global hardware policy determines DHCP packet processing, regardless of the routing instance where the DHCP configuration is applied.

  • If you don't enable the DHCP no-snoop feature, DHCP relay filters are installed at the hardware level. All DHCP packets, including unicast server replies, reach the Routing Engine for relay processing. The ACX7000 router series supports cross-VRF DHCP relay, including forward-only designs using Option 82 or the interface identifier.
  • If you enable the DHCP no-snoop feature, ACX7000 routers installs no-snoop filters globally. DHCP relay ignores transit DHCP packets and doesn't send them to the Routing Engine for relay processing. The ACX7000 router series enforces VRF local forwarding checks.

Because the no-snoop filter is applied at the global level and takes precedence over DHCP relay behavior:

  • Enabling the no-snoop statement in a single VRF instance affects DHCP processing on all VRF instances.
  • In cross-VRF DHCP relay deployments without route leaking, DHCP server unicast replies (OFFER and ACK) are dropped before the replies reach the relay process.
  • Because the packet never reaches the DHCP relay application, relay features such as forward-only-replies are not invoked and the session is not recovered.

ACX7000 routers support cross-VRF relay with no-snoop enabled only when the server VRF instance has a route to the destination address. If the destination is unreachable, the router drops DHCP OFFER and ACK messages at the hardware level, preventing clients from obtaining IP addresses. Otherwise, DHCP OFFER and ACK messages are dropped at the hardware level, preventing successful DHCP address assignment.