C H A P T E R
60-1
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
60
Configuring DHCP Snooping, IP Source Guard,
and IPSG for Static Hosts
This chapter describes how to configure Dynamic Host Configuration Protocol (DHCP) snooping, IP
source guard, and IP source guard (IPSG) for static hosts on Catalyst 4500 series switches. It provides
guidelines, procedures, and configuration examples.
This chapter consists of the following major sections:
•
About DHCP Snooping, page 60-1
•
Configuring DHCP Snooping, page 60-6
•
Displaying DHCP Snooping Information, page 60-18
•
Displaying IP Source Binding Information, page 60-23
•
Configuring IP Source Guard, page 60-20
•
Displaying IP Source Binding Information, page 60-23
•
Configuring IP Source Guard for Static Hosts, page 60-24
Note
For complete syntax and usage information for the switch commands used in this chapter, see the
Cisco IOS Command Reference Guides for the Catalyst 4500 Series Switch
If a command is not in the
Cisco Catalyst 4500 Series Switch Command Reference
, you can locate it in
the
Cisco IOS Master Command List, All Releases
About DHCP Snooping
DHCP snooping is a DHCP security feature that provides security by filtering untrusted DHCP messages
and by building and maintaining a DHCP snooping binding table. An untrusted message is a message
that is received from outside the network or firewall and that can cause traffic attacks within your
network.
The DHCP snooping binding table contains the MAC address, IP address, lease time, binding type,
VLAN number, and interface information that corresponds to the local untrusted interfaces of a switch;
it does not contain information regarding hosts interconnected with a trusted interface. An untrusted
interface is an interface that is configured to receive messages from outside the network or firewall. A
trusted interface is an interface that is configured to receive only messages from within the network.
Summary of Contents for Catalyst 4500 Series
Page 2: ......
Page 4: ......
Page 2086: ...Index IN 46 Software Configuration Guide Release IOS XE 3 9 0E and IOS 15 2 5 E ...