By configuring the function described in this chapter, you can have an alarm generated when a specified number of Dynamic Host Configuration Protocol (DHCP) packets for extending the IP address lease are discarded.
After DHCP request packet check is enabled, the device checks whether the source IP address, source MAC address, virtual local area network (VLAN) ID, and interface information carried in a received DHCP request packet match an entry in the DHCP snooping binding table. If no matching entry exists, the device considers the packet an attack packet and discards it. The device generates an alarm when the number of discarded DHCP packets for extending the IP address lease exceeds the threshold.
Configure the alarm function for discarded DHCP packets for extending the IP address lease in a VLAN, BD, or interface view.