
C
HAPTER
26
| General Security Measures
DHCP Snooping
– 629 –
C
OMMAND
U
SAGE
When the switch receives DHCP packets from clients that already include
DHCP Option 82 information, the switch can be configured to set the action
policy for these packets. The switch can either drop the DHCP packets,
keep the existing information, or replace it with the switch’s relay
information.
E
XAMPLE
Console(config)#ip dhcp snooping information policy drop
Console(config)#
ip dhcp snooping
verify mac-address
This command verifies the client’s hardware address stored in the DHCP
packet against the source MAC address in the Ethernet header. Use the
no
form to disable this function.
S
YNTAX
[
no
]
ip dhcp binding verify mac-address
D
EFAULT
S
ETTING
Enabled
C
OMMAND
M
ODE
Global Configuration
C
OMMAND
U
SAGE
If MAC address verification is enabled, and the source MAC address in the
Ethernet header of the packet is not same as the client’s hardware address
in the DHCP packet, the packet is dropped.
E
XAMPLE
This example enables MAC address verification.
Console(config)#ip dhcp snooping verify mac-address
Console(config)#
R
ELATED
C
OMMANDS
Summary of Contents for DG-FS4528P
Page 2: ......
Page 4: ......
Page 148: ...CHAPTER 5 Simple Network Management Protocol Configuring SNMPv3 Groups 148 ...
Page 389: ...CHAPTER 17 VoIP Traffic Configuration Configuring Telephony OUI 389 ...
Page 515: ...CHAPTER 22 System Management Commands UPnP 515 TTL 20 Console ...
Page 972: ......
Page 973: ...DG FS4528P ...