Layer 2 Switching Commands
345
ip dhcp snooping trust
Use the
ip dhcp snooping trust
command to configure a port as trusted. Use
the
no
form of this command to configure a port as untrusted.
Syntax
ip dhcp snooping trust
no ip dhcp snooping trust
Default Configuration
Ports are untrusted by default.
Command Mode
Interface Configuration (gigabitethernet, port-channel, tengigabitethernet,
fortygigabitethernet) mode
User Guidelines
Configuring an interface as trusted disables DHCP snooping validation of
DHCP packets and exposes the port to IPv4 DHCP DoS attacks. Configuring
an interface as untrusted indicates that the switch should firewall DHCP
messages and act as if the port is connected to a device outside the DMZ.
DHCP snooping must be enabled globally and on the VLAN for which the
port is a member for this command to have an effect.
Interfaces connected to the DHCP server must be configured as trusted in
order for DHCP snooping to operate.
Use the ip verify source command to disallow traffic from untrusted sources
on an interface.
Example
console(config-if-Gi1/0/1)#ip dhcp snooping trust
console(config-if-Gi1/0/1)#no ip dhcp snooping trust
Summary of Contents for N1100-ON
Page 2: ......
Page 4: ......
Page 258: ...Using the CLI 258 ...
Page 488: ...Layer 2 Switching Commands 488 Operational State Querier Operational version 1 ...
Page 656: ...Layer 2 Switching Commands 656 10 ...
Page 1128: ...Audio Visual Bridging Commands 1128 ...
Page 1186: ...Data Center Technology Commands 1186 ...
Page 1435: ...Layer 3 Routing Commands 1435 Number of Joins 7 Number of Groups 1 ...
Page 2330: ......
Page 2331: ...www dell com support dell com Printed in the U S A ...
Page 2332: ......