If an attack pretends to be an authorized user to send a bogus DHCP message to the DHCP server on a DHCP network, the authorized user cannot use the IP address or goes offline unexpectedly. After the DHCP snooping binding table is generated, the device can check DHCP messages against the binding table. Only messages that match the binding table can be forwarded; otherwise, the messages are discarded. This prevents unauthorized users from sending bogus DHCP messages to renew or release IP addresses.
If the function is configured in the VLAN view, it takes effect on all the interfaces in the VLAN; if the function is configured in the interface view, it takes effect only on the interface.
If the alarm threshold is configured in the system view and interface view, the smaller value takes effect.