![SMC Networks 7724M/VSW - annexe 1 Manual Download Page 332](http://html1.mh-extra.com/html/smc-networks/7724m-vsw-annexe-1/7724m-vsw-annexe-1_manual_1299754332.webp)
Management Guide
CLI
TigerAccess™ EE
SMC7824M/VSW
331
To configure the policy of DHCP option 77 on a specified port, use the following command.
Command Mode
Description
ip dhcp snooping user-class-id
port
{
replace
|
keep
}
Global
Configures the policy of DHCP option 77 field for the
DHCP Request packet (default: replace)
replace: forwards DHCP packets with user class ID
according to DHCP option 77 field format.
keep: forwards DHCP packets without any user class
ID
To delete the configured user class ID of DHCP option 77 field, use the following com-
mand.
Command Mode
Description
no ip dhcp snooping user-class-
id port
PORT
class-id
CLASS-ID
Deletes a configured user class ID of a port.
no ip dhcp snooping user-class-
id port
PORT
all
Global
Deletes all configured user class IDs of a port.
8.6.7.13
Displaying DHCP Snooping Configuration
To display DHCP snooping table, use the following command.
Command Mode
Description
show ip dhcp snooping
Shows DHCP snooping configuration.
show ip dhcp snooping binding
Enable
Global
Shows DHCP snooping binding entries.
8.6.8
IP Source Guard
IP source guard is similar to DHCP snooping. This function is used on DHCP snooping
untrusted Layer 2 port. Basically, except for DHCP packets that are allowed by DHCP
snooping process, all IP traffic comes into a port is blocked. If an authorized IP address
from the DHCP server is assigned to a DHCP client, or if a static IP source binding is con-
figured, the IP source guard restricts the IP traffic of client to those source IP addresses
configured in the binding; any IP traffic with a source IP address other than that in the IP
source binding will be filtered out. This filtering limits a host's ability to attack the network
by claiming a neighbor host's IP address.
IP source guard supports the Layer 2 port only, including both access and trunk. For each
untrusted Layer 2 port, there are two levels of IP traffic security filtering:
•
Source IP Address Filter
IP traffic is filtered based on its source IP address. Only IP traffic with a source IP
address that matches the IP source binding entry is permitted. An IP source address
filter is changed when a new IP source entry binding is created or deleted on the port,
which will be recalculated and reapplied in the hardware to reflect the IP source bind-
ing change. By default, if the IP filter is enabled without any IP source binding on the
port, a default policy that denies all IP traffic is applied to the port. Similarly, when the
IP filter is disabled, any IP source filter policy will be removed from the interface.
Summary of Contents for 7724M/VSW - annexe 1
Page 1: ......
Page 385: ...CLI Management Guide TigerAccess EE 384 SMC7824M VSW ...
Page 387: ......