MES53xx, MES33xx, MES23xx Ethernet Switch Series
159
Privileged EXEC mode commands
Command line prompt in the Privileged EXEC mode is as follows:
console#
Table 5.173. Privileged EXEC mode commands
Command
Value/Default value
Action
show dot1x interface
{gigabitethernet
gi_port
|
tengigabitethernet
te_port
|
fortygigabitethernet
fo_port
|
oob}
gi_port: (1..8/0/1..48);
te_port: (1..8/0/1..24);
fo_port: (1..8/0/1..4)
Setting up the 802.1x protocol on the interfaces (this
command is available to privileged uses only).
show dot1x users [
username
]
username: string
Show authorized clients.
show dot1x locked clients
-
Show unauthorized clients that were blocked due to timeout.
show dot1x statistics
interface
{gigabitethernet
gi_port
|
tengigabitethernet
te_port
|
fortygigabitethernet
fo_port
|
oob}
gi_port: (1..8/0/1..48);
te_port: (1..8/0/1..24);
fo_port: (1..8/0/1..4)
Show 802.1X statistics on the interfaces.
11.1.3
DHCP management and Option 82
DHCP (Dynamic Host Configuration Protocol) is a network protocol that allows the client to request
IP address and other parameters required for the proper operations in a TCP/IP network.
DHCP is used by hackers to attack devices from the client side, forcing DHCP server to report all
available addresses, and from the server side by spoofing. The switch firmware features the DHCP
snooping function that ensures device protection from attacks via DHCP.
The device discovers DHCP servers in the network and allows them to be used only via trusted
interfaces. The device also controls client access to DHCP servers using a mapping table.
DHCP Option 82 is used to inform DHCP server about the DHCP Relay Agent and the port a
particular request came from. It is used to establish mapping between IP addresses and switch ports and
ensure protection from attacks via DHCP. Option 82 contains additional information (device name, port
number) added by the switch in a DHCP Relay agent mode in the form of a DHCP request received from
the client. According to this option, DHCP server provides an IP address (IP address range) and other
parameters to the switch port. When the necessary data is received from the server, the DHCP Relay
agent provides an IP address and sends other required data to the client.
Table 5.174. Option 82 field format
Field
Information sent
Circuit ID
Device hostname.
string in the following format: eth <stacked/slotid/interfaceid>:<vlan>
The last byte is the number of the port that the device sending a DHCP
request is connected to.
Remote agent ID
Enterprise number – 0089c1
Device MAC address