19. DHCP Snooping Commands
165
19.DHCP Snooping Commands
The commands are used to allow only clients with a regular IP address
assigned by the DHCP server to communicate.
When this function is enabled, all ports are set to "untrusted." You need
to change the DHCP server and DHCP relay ports to "trusted." In
communications from clients connected on "untrusted" ports, only
DHCP packets are authenticated first and other packets are discarded.
The Switching Hub monitors communications with the DHCP server on
a "trusted" port and stores a mapping between assigned IP addresses
and MAC addresses in the Binding Table in the Switching Hub.
Only clients with an IP address and MAC address stored in the Binding
Table are authorized for normal communication.
Figure 19-1
enable dhcp_snoop
disable dhcp_snoop
show dhcp_snoop
show dhcp_snoop binding_entry { [ port <port> | vlan <vlan_name 32> | vlanid <vidlist> |
ipaddress <ipaddr> | mac_address <macaddr> ] }
Summary of Contents for ZEQUO 2200
Page 3: ...3 ...
Page 86: ...7 ARP Commands 86 ...
Page 93: ...9 Auto Configuration Commands 93 ...
Page 273: ...30 IPv6 NDP Commands 273 ...
Page 330: ...36 LLDP Commands 330 ...
Page 361: ...39 MAC based Access Control Commands 361 ...
Page 461: ...49 Protocol VLAN Commands 461 ...
Page 483: ...50 QoS Commands 483 ...
Page 504: ...53 SNMPv1 v2 v3 Commands 504 Only Administrator level users can issue this command ...
Page 523: ...53 SNMPv1 v2 v3 Commands 523 ...
Page 562: ...57 Subnet VLAN Commands 562 ...