To prevent unauthorized clients from sending Dynamic Host Configuration Protocol (DHCP) request packets to request IP addresses, the device checks whether information carried in a received DHCP request packet matches an entry in the DHCP snooping binding table. The checked information includes the source IP and MAC addresses. If a matching entry exists, the device considers the packet valid and forwards it. If no matching entry exists, the device considers the packet an attack packet and discards it.
In dynamic address assignment mode, the device generates a DHCP snooping binding table to record DHCP client information. In static address assignment mode, configure a DHCP static binding table to record DHCP client information.
Enable DHCP request packet check in a VLAN, BD, or interface view.