DHCP Option 82

Table 1. Feature History Table

Feature name

Release information

Feature description

DHCP Option 82

Release 26.2.1

Starting with Cisco IOS XE Release 26.2.1, DHCP servers on routers support DHCP Option 82 relay information. The DHCP server can use the Circuit ID and Remote ID inserted by a DHCP relay agent to select an address pool for a client. This support enables predictable, location-based IP address assignment without requiring administrators to track client MAC addresses.

DHCP Option 82

The Dynamic Host Configuration Protocol (DHCP) Option 82 feature allows the server to allocate dynamic IP addresses based on the relay information sent by the relay agent. It enables predictive IP address assignment by the server based on network switch ports.

DHCP Option 82 enables DHCP relay agents to insert additional information such as Circuit ID, Remote ID and other configuration information into DHCP request messages before forwarding them from the client to the server.

Starting with Cisco IOS XE Release 26.2.1, DHCP servers support DHCP Option 82 on routers. This platform-independent feature includes the following suboptions:

  • Circuit ID suboption: Identifies the relay agent's source interface or port where the client is connected.

  • Remote ID suboption: Identifies the relay agent.

The DHCP server allows for address reservation based on Option 82 values, enabling consistent IP assignments per interface or location.

Benefits of DHCP Option 82

The use of DHCP Option 82 provides several operational and security advantages for network management such as:

  • Predictable IP assignment: Enables static or predictable IP assignment for DHCP clients based on switch ports instead of MAC addresses.

  • Enhanced security: Improves IP address management and security.

  • Operational efficiency: Eliminates manual intervention or the need to track device MAC addresses.

  • Granular control: Allows ISPs and network administrators to map specific user accounts to physical locations, enabling consistent, location-based IP assignments.

Prerequisites

Before configuring DHCP Option 82, you must ensure these requirements are met:

  • A relay agent must be configured with global and VLAN-based DHCP snooping enabled.

  • A DHCP server is available.

  • A DHCP client is connected.

  • A relay chaining topology is present wherever applicable.

  • The client must be connected to the relay agent through an SVI interface for enabling VLAN-based snooping.

  • Class based support must be enabled on the DHCP server.


Note


You must know the hexadecimal value of each byte location in DHCP Option 82 to configure the relay-information hexadecimal command.For more information, see Circuit ID and Remote ID decode values


Key considerations

Key considerations for using DHCP Option 82 are:

  • DHCP Option 82 support must be enabled on both the relay agent and DHCP server.

  • You need to consider whether to use the DHCP Option 82 feature or not for predictable usage of IP assignment for DHCP clients.

  • You need to consider whether to enable DHCP Option 82 globally for all interfaces or selectively on specific VLANs or interfaces only.

  • You need to consider which information you want to match in the DHCP message received by the server. This can be Circuit ID, Remote ID or both.

Limitations

Limitations while using DHCP Option 82 are:

  • Support must be enabled on both the relay agent and the DHCP server for it to work properly.

  • If the DHCP server ignores DHCP Option 82, port-based deterministic assignment will not occur.

  • It is not suitable for environments where MAC based IP address assignment is required.

DHCP Option 82 packet flow

Summary

DHCP Option 82 enables network administrators to track the location information of DHCP clients by inserting additional metadata as DHCP packets traverse relay agents. This process ensures accurate IP assignment and aids in network management.

Workflow

The DHCP packet flow through a network when DHCP Option 82 is enabled is as given:

  1. The DHCP client broadcasts a DHCP request on the local network.
  2. The first DHCP relay agent intercepts the broadcast and inserts the DHCP Option 82 field, which includes suboptions such as Circuit ID and Remote ID.
  3. If a second relay agent resides closer to the DHCP server, the second relay agent encapsulates the DHCP Option 82 field coming from the first relay agent and forwards it to the DHCP server. This process preserves the information from both relay agents.
  4. The relay agent sets the gateway IP address (giaddr) field in the DHCP packet to its own IP address. The giaddr field enables the DHCP server to identify the subnet from which the request originated.
  5. The relay agent unicasts the DHCP packet to the DHCP server.
  6. The DHCP server uses the DHCP Option 82 information to determine the appropriate IP address pool and configuration parameters for the client.
  7. The DHCP server sends the reply to the relay agent using the giaddr address.
  8. The relay agent removes the DHCP Option 82 information from the reply before forwarding the DHCP reply to the client.

Hexadecimal pattern and suboption decoding

The DHCP Option 82 hexadecimal pattern can be decoded for Circuit ID and Remote ID separately as shown in the examples.

Hexadecimal pattern sample

The Option 82 hexadecimal pattern 010600040005010a020701057065747261 consists of two primary suboptions:

  • 01 06 00040005010a: Circuit ID (Suboption 1).

  • 02 07 01057065747261: Remote ID (Suboption 2).

Field Meaning
01 Circuit-ID suboption.
06 Circuit-ID length.
00040005010a Circuit-ID value.
02 Remote-ID suboption.
07 Remote-ID length.
01057065747261 Remote-ID value.

Circuit ID Decode

The Circuit ID 00040005010a identifies client’s point of attachment specifying the port and VLAN of the connected client. By default, it follows the vlan-mod-port format.

Router# show cdp neighbors
         Device ID        Local Intrfce     Holdtme    Capability  Platform  Port ID
         device1         Gig 1/10            175           R S I  ESR-6300- Gig 0/1/0
Router# show vlan brief
         VLAN          Name                             Status    Ports
         5    TURBINE_INTERNAL                 active    Gi1/10
 

Note


Decoding the Circuit ID 00040005010a:

  • 00: Default format (vlan-mod-port).

  • 04: Length (4 bytes).

  • 0005: VLAN ID (Hex 0005 = Decimal 5).

  • 010a: Module 1, Port 10 (Hex 0a = Decimal 10).


Remote ID Decode

The Remote ID 01057065747261 identifies the originating device (MAC address or Hostname). It can be configured to use the device hostname.

Router(config)# ip dhcp snooping information option format remote-id hostname

Note


Decoding the Remote ID 01057065747261:

  • 01: Hostname format.

  • 05: Length (5 bytes).

  • 7065747261: Hexadecimal ASCII for router.


Configure DHCP Option 82 on server

To configure DHCP Option 82 on Cisco IR router server, you need to follow these tasks:

  • Enable DHCP Option 82 for DHCP address allocation on the server.

  • Define the DHCP class and relay agent information patterns.

  • Define the DHCP address pool on the server.

  • Enable relay chaining on DHCP relay agents.

  • Verify DHCP Option 82

  • Debug DHCP Option 82 logs.

Follow these steps to configure DHCP Option 82 on the server.

Procedure


Step 1

Use the configure terminal command to enter global configuration mode.

Example:

Router# configure terminal

Step 2

Use the ip dhcp class class_name command to enable DHCP address allocation using DHCP class.

Example:

Router(config)# ip dhcp class class_name

Note

 
  • You can use Step 2 to enable DHCP Option 82 for DHCP address allocation on the server.

  • You can disable this functionality, without deleting the DHCP class configuration.

Step 3

Use the relay agent information command to enter relay agent information option configuration mode and define the DHCP class and relay agent information patterns.

Example:

Router(dhcp-class)# relay agent information

Note

 

The relay agent information command validates only the presence of Option 82 in the DHCP packet. It does not evaluate the Circuit ID or Remote ID. As a result, any DHCP packet containing Option 82, regardless of its source port or relay agent will match this DHCP class and be assigned an IP address.

Step 4

(Optional) Use the relay-information hex pattern [* ] [mask mask ] command to optionally specify a hexadecimal value for the full relay information option.

Example:

Router(dhcp-class-relayinfo)# relay-information hex 010600040005010a020701057065747261

Example:

Router(dhcp-class-relayinfo)# relay-information hex 01030a0b0c02050000000123 mask 0000000000000000ffffffffffffffffff

Example:

Router(dhcp-class-relayinfo)# relay-information hex 010600040005010a*

Note

 
  • The Option 82 hexadecimal pattern includes two sub options: one for Circuit ID and the other for Remote ID.

  • Each suboption can be decoded to represent the suboption type, length, VLAN, module port, client interface and MAC address.

  • You can match the hexadecimal pattern either fully or partially for specific scenarios of IP assignment.

  • You can use the mask option to mask either the Circuit ID or Remote ID partially.

  • You can use * as a wildcard pattern at the end of the hexadecimal pattern to match only the beginning of the relay information value.

  • If you omit this step, no pattern is configured and it is considered a match to any relay agent information option value, but the relay information option must be present in the DHCP packet.

  • Repeat Step 4 for each DHCP class you need to configure.


What to do next

For more information, see Configuring DHCP Address Allocation Using Option 82.

Configure DHCP address pool

Follow these steps to configure and define DHCP address pool for DHCP address allocation.

Procedure


Step 1

Use the configure terminal command to enter global configuration mode.

Example:

Router# configure terminal

Step 2

Use the ip dhcp pool name command to configure a DHCP address pool on a DHCP server and enter DHCP pool configuration mode.

Example:

Router(config)# ip dhcp pool ABC

Step 3

Use the network network-number [mask |prefix-length] command to configure the subnet number and mask for a DHCP address pool on the DHCP server.

Example:

Router(dhcp-pool)# network 10.0.20.0 255.255.0.0

Step 4

Use the class name command to associate a class with a pool and enters DHCP pool class configuration mode.

Example:

Router(dhcp-pool)# class CLASS1

Note

 

This command will also create a DHCP class if the DHCP class is not yet defined.

Step 5

Use the address range start-ip end-ip command optionally to set an address range for a DHCP class in a DHCP server address pool.

Example:

Router(dhcp-pool-class)# address range 10.0.20.1 10.0.20.100

Note

 
  • Repeat Step 5 for each DHCP class you need to associate to the DHCP pool.

  • If this command is not configured for a class, the default value is the entire subnet of the pool.


Configure DHCP relay agent

Use this task to configure the client-facing interface as a relay agent port on the router.

Procedure


Step 1

Use the configure terminal command to enter the global configuration mode.

Example:

Router# configure terminal

Step 2

Use the ip dhcp snooping command to enable the DHCP snooping feature globally

Example:

Router(config)# ip dhcp snooping

Step 3

Use the ip dhcp snooping vlan vlan-id command to enable DHCP snooping for VLAN.

Example:

Router(config)# ip dhcp snooping vlan 5

Step 4

Use these steps to configure SVI:

  1. Use the interface vlan-id command to select the SVI corresponding to the client VLAN.

    Example:

    Router(config)# interface Vlan5
  2. Use the ip address ip-address subnet-mask command to assign an IP address and subnet mask to the SVI.

    Example:

    Router(config-if)# ip address 10.166.1.1 255.255.0.0
  3. Use the ip helper-address ip-address command to specify the IP address of the DHCP server.

    Example:

    Router(config-if)# ip helper-address 110.1.1.1

Step 5

Use the interface command to select the specific interface connected to the client.

Example:

Router(config)# interface GigabitEthernet1/10 

Step 6

Use the description client command to provide a label for the client connection.

Example:

Router(config-if)# description CLIENT-1

Step 7

Use the switchport mode access command to set the interface to access mode.

Example:

Router(config-if)# switchport mode access

Step 8

Use the switchport access vlan command to assign the interface to the client VLAN.

Example:

Router(config-if)# switchport access vlan 5

Step 9

(Optional) Use these commands to define custom Circuit ID and Remote ID values, overriding the defaults:

  1. (Optional) Use the ip dhcp snooping vlan vlan-id information option format-type circuit-id string circuit-id-string command to override the default Circuit ID (vlan mod port ) with a user-defined string.

    Example:

    Router(config-if)# ip dhcp snooping vlan 5 information option format-type circuit-id string abc
  2. (Optional) Use the ip dhcp snooping information option format remote-id string remote-id-string command to override the default Remote ID (MAC address) with a user-defined string.

    Example:

    Router(config)# ip dhcp snooping information option format remote-id string abc
  3. Use the exit command to return to global configuration mode.

    Example:

    Router(config-if)# exit

What to do next

For more information, see Configuring the Cisco IOS XE DHCP Relay Agent.

Configure relay chaining on relay agents

Use this task to configure relay chaining when multiple relay agents are used in the network. Enabling encapsulation on the secondary relay agent ensures that the original DHCP Option 82 data is preserved as the request is forwarded to the DHCP server.

Before you begin


Note


  • Ensure DHCP snooping is enabled on both relay agents for their respective client VLANs.

  • Relay chaining requires that DHCP snooping be enabled on both relay agents for their respective client VLANs. Ensure that interfaces are correctly configured between the relay agents to allow the passage of DHCP traffic.


Procedure


Step 1

Use the configure terminal command to enter the global configuration mode.

Example:

Router# configure terminal

Step 2

Use the ip dhcp relay information option vpn command to enable the inclusion of VPN information in the relay agent inforamtion.

Example:

Router(config)# ip dhcp relay information option vpn

Step 3

Use the ip dhcp relay information policy encapsulate command to enable the encapsulation policy on the secondary relay agent.

Example:

Router(config)# ip dhcp relay information policy encapsulate

Note

 

In a double relay agent scenario, this configuration must be applied on the relay agent closest to the server.

Step 4

Use the exit command to return to privileged EXEC mode.

Example:

Router(config)# exit

An example of an encapsulated hexadecimal pattern format received by server in relay chaining is as given:

091f000000091a0a18bea80a0152120106000401f401050208000668d972ad3540020c020a00003c3c3c010e000000

Verify DHCP Option 82

Use these steps to verify DHCP Option 82 configuration.

Procedure


Step 1

Use these commands on the DHCP server side:

  1. Use the more system:running-config command to display the running configuration.

    Example:

    Router# show running-config

    Note

     

    This command will display the configured DHCP classes and DHCP pools.

  2. Use the show ip dhcp binding command to display the client's MAC IP address.

    Example:

    Router# show ip dhcp binding

Step 2

Use these commands on the DHCP relay agent side:

  1. Use the show ip dhcp snooping binding command to verify the relay agent's snooping bindings.

    Example:

    Router# show ip dhcp snooping binding
  2. Use the show ip dhcp snooping command to validate the Circuit ID and Remote ID.

    Example:

    Router# show ip dhcp snooping

Debug DHCP Option 82 logs

Use this task to troubleshoot DHCP Option 82 configurations and derive the required hexadecimal patterns for class matching by enabling debug logs on both the DHCP server and the relay agent.

Procedure


Step 1

Use the debug ip dhcp server command on the DHCP server to monitor server-side events, classes, and packets.

Example:

Router# debug ip dhcp server event
         Router# debug ip dhcp server class
         Router# debug ip dhcp server packet

Step 2

Use the debug ip dhcp snooping command on the relay agent to monitor snooping events, agent processing, and packets.

Example:

Router# debug ip dhcp snooping agent
         Router# debug ip dhcp snooping event
         Router# debug ip dhcp snooping packet

Note

 

You can analyze the generated logs to identify the relay-information hexadecimal pattern being received by the server.

Example:

*May 13 2026 08:25:19.629: DHCPD: Searching for a match to 'relay-information 010600040005010a020701057065747261' in class class_turbine
          *May 13 2026 08:25:19.629: DHCPD: input pattern 'relay-information 010600040005010a020701057065747261' matches class CLASS1