Chapter 24: General Security Measures
DHCPv6 Snooping
– 860 –
count
- Maximum number of entries. (Range: 1-5)
D
EFAULT
S
ETTING
5
C
OMMAND
M
ODE
Interface Configuration (Ethernet, Port Channel)
E
XAMPLE
This example sets the maximum number of binding entries to 1.
Console(config)#interface ethernet 1/1
Console(config-if)#ipv6 dhcp snooping max-binding 1
Console(config-if)#
ipv6 dhcp snooping
trust
This command configures the specified interface as trusted. Use the
no
form to restore the default setting.
S
YNTAX
[
no
]
ipv6 dhcp snooping trust
D
EFAULT
S
ETTING
All interfaces are untrusted
C
OMMAND
M
ODE
Interface Configuration (Ethernet, Port Channel)
C
OMMAND
U
SAGE
•
A trusted interface is an interface that is configured to receive only
messages from within the network. An untrusted interface is an
interface that is configured to receive messages from outside the
network or fire wall.
•
Set all ports connected to DHCv6 servers within the local network or
fire wall to trusted, and all other ports outside the local network or fire
wall to untrusted.
•
When DHCPv6 snooping is enabled globally using the
command, and enabled on a VLAN with
command, DHCPv6 packet filtering will be performed on any
untrusted ports within the VLAN according to the default status, or as
specifically configured for an interface with the
no
ipv6 dhcp snooping
trust
command.
•
When an untrusted port is changed to a trusted port, all the dynamic
DHCPv6 snooping bindings associated with this port are removed.
•
Additional considerations when the switch itself is a DHCPv6 client
–
The port(s) through which it submits a client request to the DHCPv6
server must be configured as trusted.
Summary of Contents for SSE-G2252
Page 42: ...44 General IP Routing on page 627...
Page 603: ...Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 609...
Page 883: ...Chapter 24 General Security Measures Port based Traffic Segmentation 894...
Page 989: ...Chapter 30 Congestion Control Commands Automatic Traffic Control Commands 1000 Console...
Page 1007: ...Chapter 33 Address Table Commands 1019...
Page 1137: ...Chapter 38 Quality of Service Commands 1150...