General Security Measures
4-169
4
Command Usage
If MAC address verification is enabled, and the source MAC address in the
Ethernet header of the packet is not same as the client’s hardware address in
the DHCP packet, the packet is dropped.
Example
This example enables MAC address verification.
Related Commands
ip dhcp snooping (4-165)
ip dhcp snooping vlan (4-167)
ip dhcp snooping trust (4-167)
ip dhcp snooping information option
This command enables the DHCP Option 82 information relay for the switch. Use
the
no
form to disable this function.
Syntax
[
no
]
ip dhcp snooping information option
Default Setting
Disabled
Command Mode
Global Configuration
Command Usage
• DHCP provides a relay mechanism for sending information about the switch
and its DHCP clients to the DHCP server. Known as DHCP Option 82, it
allows compatible DHCP servers to use the information when assigning IP
addresses, or to set other services or policies for clients.
• When the DHCP Snooping Information Option is enabled, the requesting
client (or an intermediate relay agent that has used the information fields to
describe itself) can be identified in the DHCP request packets forwarded by
the switch and in reply packets sent back from the DHCP server by the switch
port to which they are connected rather than just their MAC address. DHCP
client-server exchange messages are then forwarded directly between the
server and client without having to flood them to the entire VLAN.
• DHCP snooping must be enabled on the switch for the DHCP Option 82
information to be inserted into packets.
• Use the
ip dhcp snooping information option
command (page 4-169) to
specify how to handle DHCP client request packets which already contain
Option 82 information.
Console(config)#ip dhcp snooping verify mac-address
Console(config)#
Summary of Contents for iES4028F
Page 1: ...iES4028F 4028FP 4024GP ...
Page 4: ...iv This page is intentionally left blank ...
Page 10: ...x This page is intentionally left blank ...
Page 28: ...Contents xxviii This page is intentionally left blank ...
Page 32: ...Tables xxxii This page is intentionally left blank ...
Page 46: ...Introduction 1 10 1 This page is intentionally left blank ...
Page 336: ...Configuring the Switch 3 280 3 This page is intentionally left blank ...
Page 688: ...Command Line Interface 4 352 4 This page is intentionally left blank ...
Page 702: ...Glossary Glossary 8 This page is intentionally left blank ...
Page 710: ...Index 8 Index This page is intentionally left blank ...
Page 711: ...This page is intentionally left blank ...
Page 712: ...iES4028F 4028FP 4024GP ...