![Cisco Catalyst Blade 3032 Скачать руководство пользователя страница 564](http://html.mh-extra.com/html/cisco/catalyst-blade-3032/catalyst-blade-3032_software-configuration-manual_67665564.webp)
22-16
Cisco Catalyst Blade Switch 3130 and 3032 for Dell Software Configuration Guide
OL-13270-06
Chapter 22 Configuring DHCP Features and IP Source Guard
Displaying DHCP Snooping Information
Displaying DHCP Snooping Information
To display the DHCP snooping information, use one or more of the privileged EXEC commands in
Table 22-2
:
Note
If DHCP snooping is enabled and an interface changes to the down state, the switch does not delete the
statically configured bindings.
Understanding IP Source Guard
IPSG is a security feature that restricts IP traffic on nonrouted, Layer 2 interfaces by filtering traffic
based on the DHCP snooping binding database and on manually configured IP source bindings. You can
use IP source guard to prevent traffic attacks if a host tries to use the IP address of its neighbor.
You can enable IP source guard when DHCP snooping is enabled on an untrusted interface. After IPSG
is enabled on an interface, the switch blocks all IP traffic received on the interface except for DHCP
packets allowed by DHCP snooping. A port access control list (ACL) is applied to the interface. The port
ACL allows only IP traffic with a source IP address in the IP source binding table and denies all other
traffic.
Note
The port ACL takes precedence over any router ACLs or VLAN maps that affect the same interface.
The IP source binding table bindings are learned by DHCP snooping or are manually configured (static
IP source bindings). An entry in this table has an IP address, its associated MAC address, and its
associated VLAN number. The switch uses the IP source binding table only when IP source guard is
enabled.
Table 22-2
Commands for Displaying DHCP Information
Command
Purpose
show ip dhcp snooping
Displays the DHCP snooping configuration for a switch
show ip dhcp snooping binding
Displays only the dynamically configured bindings in the DHCP snooping binding
database, also referred to as a binding table.
show ip dhcp snooping database
Displays the DHCP snooping binding database status and statistics.
show ip dhcp snooping statistics
Displays the DHCP snooping statistics in summary or detail form.
show ip source binding
Display the dynamically and statically configured bindings.
Содержание Catalyst Blade 3032
Страница 46: ...Contents xlvi Cisco Catalyst Blade Switch 3130 and 3032 for Dell Software Configuration Guide OL 13270 06 ...
Страница 50: ...lii Cisco Catalyst Blade Switch 3130 and 3032 for Dell Software Configuration Guide OL 13270 06 Preface ...
Страница 1380: ...Index IN 54 Cisco Catalyst Switch Module 3110 and 3012 for IBM BladeCenter Software Configuration Guide OL 12189 06 ...