24. DHCP Snooping Commands
310
24.DHCP Snooping Commands
The commands are used to allow only clients with a regular IP address
assigned by the DHCP server to communicate.
When this function is enabled, all ports are set to "untrusted." You need
to change the DHCP server and DHCP relay ports to "trusted." In
communications from clients connected on "untrusted" ports, only
DHCP packets are authenticated first and other packets are discarded.
The Switching Hub monitors communications with the DHCP server on
a "trusted" port and stores a mapping between assigned IP addresses
and MAC addresses in the Binding Table in the Switching Hub.
Only clients with an IP address and MAC address stored in the Binding
Table are authorized for normal communication.
Figure 24-1
enable dhcp_snoop
disable dhcp_snoop
show dhcp_snoop
show dhcp_snoop binding_entry { [ port <port> | vlan <vlan_name 32> | vlanid <vidlist> |
ipaddress <ipaddr> | mac_address <macaddr> ] }
Summary of Contents for ZEQUO 6400
Page 160: ...12 Basic IP Commands 161 ...
Page 189: ...17 Command Logging Command List 190 ...
Page 554: ...49 MAC based Access Control Commands 555 ...
Page 812: ...69 QoS Commands 813 ...
Page 839: ...73 SNMPv1 v2 v3 Commands 840 Only Administrator level users can issue this command ...
Page 962: ...85 Virtual Router Redundancy Protocol VRRP Command List 963 ...
Page 1050: ...91 System Log Lists 1051 ...