Chapter 24: General Security Measures
DHCPv6 Snooping
– 854 –
DHCP
V
6 S
NOOPING
DHCPv6 snooping allows a switch to protect a network from rogue DHCPv6
servers or other devices which send port-related information to a DHCPv6
server. This information can be useful in tracking an IP address back to a
physical port. This section describes commands used to configure DHCPv6
snooping.
ipv6 dhcp snooping
This command enables DHCPv6 snooping globally. Use the
no
form to
restore the default setting.
S
YNTAX
[
no
]
ipv6 dhcp snooping
D
EFAULT
S
ETTING
Disabled
C
OMMAND
M
ODE
Global Configuration
C
OMMAND
U
SAGE
•
Network traffic may be disrupted when malicious DHCPv6 messages are
received from an outside source. DHCPv6 snooping is used to filter
DHCPv6 messages received on an unsecure interface from outside the
network or fire wall. When DHCPv6 snooping is enabled globally by this
command, and enabled on a VLAN interface by the
command, DHCP messages received on an untrusted interface (as
Table 24-9: DHCP Snooping Commands
Command
Function
Mode
Enables DHCPv6 snooping globally
GC
Enables insertion of DHCPv6 Option 37 relay agent
remote-id
GC
Sets the information option policy for DHCPv6 client
packets that include Option 37 information
GC
Enables DHCPv6 snooping on the specified VLAN
GC
Sets the maximum number of entries which can be
stored in the binding database for an interface
IC
Configures the specified interface as trusted
IC
Clears DHCPv6 snooping binding table entries from
RAM
PE
Removes all dynamically learned snooping entries
from flash memory.
PE
Shows the DHCPv6 snooping configuration settings PE
Shows the DHCPv6 snooping binding table entries
PE
Shows statistics for DHCPv6 snooping client, server
and relay packets
PE
Summary of Contents for SSE-G2252
Page 42: ...44 General IP Routing on page 627...
Page 603: ...Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 609...
Page 883: ...Chapter 24 General Security Measures Port based Traffic Segmentation 894...
Page 989: ...Chapter 30 Congestion Control Commands Automatic Traffic Control Commands 1000 Console...
Page 1007: ...Chapter 33 Address Table Commands 1019...
Page 1137: ...Chapter 38 Quality of Service Commands 1150...