Chapter 9
| General Security Measures
DHCPv4 Snooping
– 273 –
show web-auth
summary
This command displays a summary of web authentication port parameters and
statistics.
Command Mode
Privileged Exec
Example
Console#show web-auth summary
Global Web-Auth Parameters
System Auth Control : Enabled
Port Status Authenticated Host Count
---- ------ ------------------------
1/ 1 Disabled 0
1/ 2 Enabled 8
1/ 3 Disabled 0
1/ 4 Disabled 0
1/ 5 Disabled 0
.
.
.
DHCPv4 Snooping
DHCPv4 snooping allows a switch to protect a network from rogue DHCPv4 servers
or other devices which send port-related information to a DHCPv4 server. This
information can be useful in tracking an IP address back to a physical port. This
section describes commands used to configure DHCPv4 snooping.
Table 54: DHCP Snooping Commands
Command
Function
Mode
Enables DHCP snooping globally
GC
Enables or disables the use of DHCP Option 82
information, and specifies frame format for the
remote-id
GC
Disables use of sub-type and sub-length for the
CID/RID in Option 82 information
GC
Sets the remote ID to the switch’s IP address, MAC
address, or arbitrary string, TR-101 compliant node
identifier, or removes VLAN ID from the end of the
TR101 field
GC
Sets the board identifier used in Option 82 information
based on TR-101 syntax
GC
Sets the information option policy for DHCP client
packets that include Option 82 information
GC
Verifies the client’s hardware address stored in the
DHCP packet against the source MAC address in the
Ethernet header
GC
Enables DHCP snooping on the specified VLAN
GC