This topic describes DHCP relay agent Option 82 support on the Cisco 8000 Series Router, which lets you insert Circuit ID and Remote ID suboptions per Ethernet Flow Point (EFP) or per ingress Layer 2 interface into forwarded DHCP packets.
In forwarded BOOTREQUEST messages to a DHCP server, you can configure the relay agent to insert Option 82 suboptions in the DHCP packet. The Option 82 suboptions available for configuration are Circuit ID and Remote ID. When a DHCP relay profile is attached to a Bridge Virtual Interface (BVI), you can assign the Option 82 Circuit ID and Remote ID per EFP or per ingress Layer 2 interface. The relay agent then sends the DHCP packet to the server with the included Option 82 Circuit ID or Remote ID. DHCP relay agent Option 82 provides security when DHCP is used to allocate network addresses. Thus, you can enable the DHCP relay agent to prevent DHCP client requests from untrusted sources.
|
Feature Name |
Release |
Description |
|---|---|---|
|
Option 82 support in DHCP packets |
Release 26.3.1 |
Introduced in this release on: Modular Systems (8800 [LC ASIC: K100])(select variants only*) *This feature is supported on Cisco 88-LC1-48Y8F-EM line cards. |
|
Option 82 support in DHCP packets |
Release 26.2.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100]) This feature support is supported on:
|
|
Option 82 support in DHCP packets |
Release 26.1.1 |
Introduced in this release on: Centralized Systems (8400 [ASIC: K100])(select variants only*) *This feature is supported on Cisco 8404-SYS-D router. |
|
Option 82 support in DHCP packets |
Release 25.4.1 |
Introduced in this release on: Fixed Systems (8700 [ASIC: K100])(select variants only*) * This feature is supported on:
|
|
Option 82 support in DHCP packets |
Release 25.1.1 |
Introduced in this release on: Modular Systems (8800 [LC ASIC: P100]) (select variants only*) By utilizing DHCP relay agent Option 82 functionality, you can now enhance the network security by ensuring that DHCP allocates network addresses only to trusted sources. This reduces the risk of unauthorized devices gaining network access. You can achieve this by assigning Option 82 Circuit ID and Remote ID per Ethernet Flow Points (EFP) or per ingress Layer 2 interface in the DHCP packet. *This feature is supported on:
|