DHCP Snooping Commands
367
12
DHCP Snooping Commands
DHCP Snooping is a security feature that monitors DHCP messages between
DHCP clients and DHCP server to filter harmful DHCP messages and build
a bindings database of {MAC address, IP address, VLAN ID, interface} tuples
that are considered authorized.
The DHCP snooping application processes incoming DHCP messages. For
DHCPRELEASE and DHCPDECLINE messages, the application compares
the receive interface and VLAN with the client's interface and VLAN in the
bindings database. If the interfaces do not match, the application logs the
event and drops the message. For valid client messages, DHCP snooping
compares the source MAC address to the DHCP client hardware address.
When there is a mismatch, DHCP snooping logs and drops the packet.
DHCP Snooping forwards valid client messages on trusted members within
the VLAN. If DHCP Relay and/or DHCP Server coexist with DHCP
Snooping, the DHCP client message is sent to the DHCP Relay or/and
DHCP Server for further processing.
The DHCP Snooping application uses DHCP messages to build and
maintain the binding's database. The binding's database only includes data
for clients on untrusted ports. DHCP Snooping creates a tentative binding
from DHCP DISCOVER and REQUEST messages. Tentative bindings tie a
client to a port (the port where the DHCP client message was received).
Tentative bindings are completed when DHCP Snooping learns the client's IP
address from a DHCP ACK message on a trusted port. DHCP Snooping
removes bindings in response to DECLINE, RELEASE, and NACK messages.
The DHCP Snooping application ignores the ACK messages as a reply to the
DHCP Inform messages received on trusted ports. The network administrator
can enter static bindings into the binding database.
IP Source Guard and Dynamic ARP Inspection use the DHCP Snooping
bindings database for the validation of IP and ARP packets.
2CSPC4.X7000-SWUM204.book Page 367 Friday, March 15, 2013 8:22 AM
Содержание Networking 7048
Страница 76: ...Contents 76 ...
Страница 168: ...Command Groups 168 ...
Страница 242: ...Using the CLI 242 ...
Страница 244: ...244 Layer 2 Switching Commands ...
Страница 278: ...278 AAA Commands ...
Страница 287: ...Administrative Profiles Commands 287 global config ethernet config port channel config ...
Страница 288: ...288 Administrative Profiles Commands ...
Страница 326: ...326 Address Table Commands Maximum addresses 100 Learned addresses ...
Страница 332: ...332 Auto VoIP Commands ...
Страница 366: ...366 DHCP Management Interface Commands ...
Страница 464: ...464 Ethernet CFM Commands ...
Страница 478: ...478 Green Ethernet Commands ...
Страница 502: ...502 IGMP Snooping Commands ...
Страница 542: ...542 IPv6 Access List Commands ...
Страница 554: ...554 IPv6 MLD Snooping Commands ...
Страница 568: ...568 IP Source Guard Commands ...
Страница 580: ...580 iSCSI Optimization Commands ...
Страница 588: ...588 Link Dependency Commands ...
Страница 616: ...616 LLDP Commands ...
Страница 652: ...652 Port Channel Commands ...
Страница 656: ...656 Port Monitor Commands Session ID Admin Mode Probe Port Mirrored Port Type 1 Enable 1 0 10 1 0 8 Rx Tx ...
Страница 752: ...752 RADIUS Commands ...
Страница 784: ...784 Spanning Tree Commands ...
Страница 850: ...850 VLAN Commands ...
Страница 856: ...856 Voice VLAN Commands ...
Страница 888: ...888 802 1x Commands console show dot1x advanced gigabitethernet 1 0 2 Port Guest Unauthenticated VLAN Vlan 1 0 2 10 20 ...
Страница 890: ...890 Layer 3 Commands ...
Страница 934: ...934 DHCP Server and Relay Agent Commands ...
Страница 952: ...952 DHCPv6 Commands DHCPv6 Relay forward Packets Transmitted 0 Total DHCPv6 Packets Transmitted 0 ...
Страница 960: ...960 DVMRP Commands ...
Страница 980: ...980 IGMP Commands ...
Страница 988: ...988 IGMP Proxy Commands ...
Страница 1036: ...1036 IP Routing Commands ...
Страница 1109: ...IPv6 Routing Commands 1109 Tracing route over a maximum of 20 hops 1 N N N ...
Страница 1110: ...1110 IPv6 Routing Commands ...
Страница 1114: ...1114 Loopback Interface Commands ...
Страница 1144: ...1144 Multicast Commands ...
Страница 1296: ...1296 OSPFv3 Commands ...
Страница 1306: ...1306 Router Discovery Protocol Commands ...
Страница 1322: ...1322 Routing Information Protocol Commands console config router split horizon none ...
Страница 1328: ...1328 Tunnel Interface Commands ...
Страница 1354: ...1354 Utility Commands ...
Страница 1364: ...1364 Auto Install Commands ...
Страница 1406: ...1406 CLI Macro Commands ...
Страница 1424: ...1424 Clock Commands ...
Страница 1430: ...1430 Command Line Configuration Scripting Commands ...
Страница 1451: ...Configuration and Image File Commands 1451 console ...
Страница 1452: ...1452 Configuration and Image File Commands ...
Страница 1482: ...1482 Mode Commands ...
Страница 1517: ...Power Over Ethernet Commands 1517 Command Mode Privileged EXEC User Guidelines This command has no user guidelines ...
Страница 1518: ...1518 Power Over Ethernet Commands ...
Страница 1576: ...1576 Sflow Commands ...
Страница 1604: ...1604 SNMP Commands ...
Страница 1618: ...1618 SSH Commands ...
Страница 1640: ...1640 Syslog Commands ...
Страница 1708: ...1708 System Management Commands 5 ...
Страница 1716: ...1716 Terminal Length Commands ...
Страница 1734: ...1734 User Interface Commands Example The following example closes an active terminal session console quit ...
Страница 1786: ...1786 Appendix A List of Commands ...
Страница 1787: ...www dell com support dell com Printed in the U S A ...
Страница 1788: ......