[c-nsp] Performace - IP DHCP Snooping

Alexander Clouter alex at digriz.org.uk
Sun Aug 14 11:36:11 EDT 2011


* Andrew Miehs <andrew at 2sheds.de> [2011-08-14 17:20:35+0200]:
>
> On 14/08/2011, at 12:56 PM, Alexander Clouter wrote:
> > Two gotchas:
> > * 'ip dhcp snooping database flash:dhcp-snoop.db', so that if the 
> > 	switch reboots all the clients do not get locked out
> 
> I don't understand why you would require storing this data?
> 
> The dhcp servers are on the trusted ports - and clients are all on untrusted.
> What more information needs to be stored?
> 
http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SXF/native/configuration/guide/snoodhcp.html#wp1090370

Switch reloads occur for many reasons (power failures, IOS updates, etc) 
and you do not want all the workstations hanging off that switch being 
dead in the water when/if they do not renew their lease...

Cheers

-- 
Alexander Clouter
.sigmonster says: Computers are not intelligent.  They only think they are.


More information about the cisco-nsp mailing list