Chapter 24: General Security Measures
DHCPv4 Snooping
– 843 –
DHCP
V
4 S
NOOPING
DHCPv4 snooping allows a switch to protect a network from rogue DHCPv4
servers or other devices which send port-related information to a DHCPv4
server. This information can be useful in tracking an IP address back to a
physical port. This section describes commands used to configure DHCPv4
snooping.
ip dhcp snooping
This command enables DHCP snooping globally. Use the
no
form to restore
the default setting.
S
YNTAX
[
no
]
ip dhcp snooping
D
EFAULT
S
ETTING
Disabled
C
OMMAND
M
ODE
Global Configuration
Table 24-7: DHCP Snooping Commands
Command
Function
Mode
Enables DHCP snooping globally
GC
Enables or disables the use of DHCP Option 82
information, and specifies frame format for the
remote-id
GC
Sets the information option policy for DHCP client
packets that include Option 82 information
GC
Sets the maximum number of DHCP packets that can
be trapped for DHCP snooping
GC
Verifies the client’s hardware address stored in the
DHCP packet against the source MAC address in the
Ethernet header
GC
Enables DHCP snooping on the specified VLAN
GC
Enables or disables the use of DHCP Option 82
information circuit-id suboption
IC
Configures the specified interface as trusted
IC
Clears DHCP snooping binding table entries from
RAM
PE
Removes all dynamically learned snooping entries
from flash memory.
PE
Writes all dynamically learned snooping entries to
flash memory
PE
Shows the DHCP snooping configuration settings
PE
Shows the DHCP snooping binding table entries
PE
Summary of Contents for SSE-G2252
Page 42: ...44 General IP Routing on page 627...
Page 603: ...Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 609...
Page 883: ...Chapter 24 General Security Measures Port based Traffic Segmentation 894...
Page 989: ...Chapter 30 Congestion Control Commands Automatic Traffic Control Commands 1000 Console...
Page 1007: ...Chapter 33 Address Table Commands 1019...
Page 1137: ...Chapter 38 Quality of Service Commands 1150...