![Digisol DG-GS1550 Management Manual Download Page 447](http://html.mh-extra.com/html/digisol/dg-gs1550/dg-gs1550_management-manual_2498037447.webp)
General Security Measures
4-147
4
ip dhcp snooping trust
This command configures the specified interface as trusted. Use the
no
form to
restore the default setting.
Syntax
[
no
]
ip dhcp snooping trust
Default Setting
All interfaces are untrusted
Command Mode
Interface Configuration (Ethernet, Port Channel)
Command Usage
• A trusted interface is an interface that is configured to receive only messages
from within the network. An untrusted interface is an interface that is
configured to receive messages from outside the network or fire wall.
• Set all ports connected to DHCP servers within the local network or fire wall
to trusted, and all other ports outside the local network or fire wall to untrusted.
• When DHCP snooping ia enabled globally using the
command (page 4-144), and enabled on a VLAN with
command (page 4-146), DHCP packet filtering will be performed on any
untrusted ports within the VLAN according to the default status, or as
specifically configured for an interface with the
no ip dhcp snooping trust
command.
• When an untrusted port is changed to a trusted port, all the dynamic DHCP
snooping bindings associated with this port are removed.
•
Additional considerations when the switch itself is a DHCP client
– The port(s)
through which it submits a client request to the DHCP server must be
configured as trusted.
Example
This example sets port 5 to untrusted.
Related Commands
ip dhcp snooping (4-144)
ip dhcp snooping vlan (4-146)
Console(config)#interface ethernet 1/5
Console(config-if)#no ip dhcp snooping trust
Console(config-if)#
Summary of Contents for DG-GS1550
Page 24: ...Tables xxx ...
Page 46: ...Initial Configuration 2 10 2 ...
Page 642: ...Command Line Interface 4 342 4 ...
Page 664: ...Index 8 Index ...
Page 665: ......