11-10
Configuring Advanced Threat Protection
DHCP Snooping
Changing the Remote-id from a MAC to an IP Address
By default, DHCP snooping uses the MAC address of the switch as the remote-
id in Option 82 additions. The IP address of the VLAN the packet was received
on or the IP address of the management VLAN can be used instead by entering
this command with the associated parameter:
HP Switch(config)# dhcp-snooping option 82 remote-id
<mac|subnet-ip|mgmt-ip>
Figure 11-6. Example of DHCP Snooping Option 82 using the VLAN IP Address
Disabling the MAC Address Check
DHCP snooping drops DHCP packets received on untrusted ports when the
check address (chaddr) field in the DHCP header does not match the source
MAC address of the packet (default behavior). To disable this checking, use
the
no
form of this command.
HP Switch(config)# dhcp-snooping verify mac
HP Switch(config)# dhcp-snooping option 82 remote-id subnet-
ip
HP Switch(config)# show dhcp-snooping
DHCP Snooping Information
DHCP Snooping : Yes
Enabled Vlans : 4
Verify MAC : Yes
Option 82 untrusted policy : drop
Option 82 Insertion : Yes
Option 82 remote-id : subnet-ip
Summary of Contents for E3800 Series
Page 2: ......
Page 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Page 30: ...xxviii ...
Page 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Page 186: ...4 72 Web and MAC Authentication Client Status ...
Page 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Page 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 730: ...20 Index ...
Page 731: ......