DHCP Snooping Option 82 Blocking DHCP Addresses on SW3?

Troubleshoot IPv4 and IPv6 DHCP (DHCP client, IOS DHCP server, DHCP relay, DHCP options)
Answer Correct answer: B — Disable DHCP Option 82 insertion on SW3 with `no ip dhcp snooping information option` so DHCP requests are not dropped.

Refer to the exhibit. HostA and HostB cannot receive IP addresses from the DHCP server. The switches are configured with the DHCP snooping. Which configuration on SW3 resolves the issue? - image - image

  1. ip dhcp relay information option-insert
  2. no ip dhcp snooping information option Correct Answer
  3. ip dhcp server use subscriber-id client-id
  4. ip helper-address 1.0.0.2

Community Votes

B
67%
D
33%

67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests DHCP snooping Option 82 handling across multiple switches; the trap is assuming a missing ip helper-address (D) rather than the snooping option mismatch.

HostA and HostB fail to get DHCP addresses because SW3 drops requests carrying Option 82 inserted by an upstream snooping switch. The fix is to disable Option 82 insertion on SW3 with no ip dhcp snooping information option (B).

Choosing `ip helper-address 1.0.0.2` (D), but the DHCP server is reachable via relay already and the failure is caused by DHCP snooping rejecting Option 82, not a missing relay.

Community Discussion (5 comments)

Brahim90 👍 3 Selected: B
Correct answer is B. The reason why D is incorrect because the ip helper address for ipv6 is different from ipv4. R1# config t Enter configuration commands, one per line. End with CNTL/Z. R1(config)# interface gigabitethernet0/0 R1(config-if)# ipv6 dhcp relay destination 2001:db8:a:b::7
Anarky19 👍 4 Selected: D
Why not D? The dhcp server is in a different subnet/vlan 1.0.0.0/30 than hosts (vlan 5 for host A 10.5.5.0/24 and vlan 6 for host B 10.6.6.0/24) I can't see in the log messages something like: DHCP_SNOOPING: invalid DHCP options - unable to parse In conclusion, why do you think B is the best answer?
leipeG 👍 2
The "no ip dhcp snooping information option command" disables the insertion of DHCP Option 82. This might be necessary in certain environments where devices (like older DHCP servers or clients) do not support or need Option 82 information.
dapardo 👍 3 Selected: B
Im going with B considering this information: https://community.cisco.com/t5/switching/dhcp-snooping-clients-not-getting-ip-address/td-p/1749969
Gesti 👍 1
It's B

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The exhibit shows HostA and HostB failing to obtain IP addresses even though DHCP snooping is enabled. In a multi-switch topology, an intermediate switch running DHCP snooping inserts Option 82 into DHCP requests received on untrusted ports. When those requests reach another snooping switch or a DHCP server that does not expect Option 82, the packets can be dropped. On SW3, which sits between the hosts and the DHCP server, the no ip dhcp snooping information option command stops SW3 from adding Option 82, allowing the DHCP requests to be forwarded normally. This matches Cisco's recommended fix for situations where clients behind a second snooping switch cannot get addresses, as referenced in the community thread.

Why the Other Options Are Wrong

ip dhcp relay information option-insert (A) is a relay-agent command that enables Option 82 insertion, not a fix for unwanted insertion. ip dhcp server use subscriber-id client-id (C) is a DHCP server command that changes the client identifier used for lease lookup; it has no effect on snooping behavior on SW3. ip helper-address 1.0.0.2 (D) configures a relay address for a Layer 3 interface, but the failure is not a missing relay—DHCP requests are already being relayed (or SW3 is not the Layer 3 gateway). As Anarky19 pointed out, the DHCP server sits in a different subnet and no invalid-option log was observed, which suggests the issue is the snooping Option 82 handling rather than the helper address.

Community Comment Notes

Anarky19 questioned why D is not correct, noting the server is in a different VLAN and no invalid DHCP options log appeared, but the majority still favored B. Brahim90 confirmed B and highlighted that IPv6 DHCP relay uses a different command (ipv6 dhcp relay destination), which is irrelevant here. dapardo linked a Cisco community discussion about DHCP snooping clients not getting IP addresses, which supports disabling Option 82 insertion. leipeG explained that no ip dhcp snooping information option disables Option 82 insertion, which is sometimes necessary for older DHCP servers or clients. Gesti simply agreed with B.

Official Reference

Exam Strategy

When DHCP snooping is enabled on multiple switches, remember that Option 82 can cause silent drops. Check for no ip dhcp snooping information option on intermediate switches before troubleshooting Layer 3 relay configurations.

Frequently Asked Questions

Why is `ip helper-address 1.0.0.2` (D) not the correct answer?

The DHCP server is already reachable via relay, and the failure is caused by DHCP snooping dropping Option 82-tagged packets, not by a missing helper address on SW3.

What does `no ip dhcp snooping information option` do?

It disables the insertion of DHCP Option 82 by the switch, preventing the switch from adding information that can cause upstream devices to drop DHCP requests.

Related Analysis

Practice All 300-410 Questions

Access 159 questions with complete answers and detailed explanations.

View Full 300-410 Practice Test →

← Back to 300-410 Study Guide