
set dhcpsnooping trust
17-6
DHCP Snooping and Dynamic ARP Inspection
Mode
Switch
command,
read
‐
write.
Usage
When
a
switch
learns
of
new
bindings
or
when
it
loses
bindings,
the
switch
updates
the
entries
in
the
bindings
database
according
to
the
write
delay
timer.
The
switch
also
updates
the
entries
in
the
binding
file.
The
frequency
at
which
the
file
is
updated
is
based
on
the
delay
configured
with
this
command,
and
the
updates
are
batched.
Example
The
following
example
specifies
that
the
stored
database
should
be
updated
once
an
hour.
C3(rw)->set dhcpsnooping database write-delay 3600
set dhcpsnooping trust
Use
this
command
to
enable
or
disable
a
port
as
a
DHCP
snooping
trusted
port.
Syntax
set dhcpsnooping trust port
port-string
{
enable
|
disable
}
Parameters
Defaults
By
default,
ports
are
untrusted.
Mode
Switch
command,
read
‐
write.
Usage
In
order
for
DHCP
snooping
to
operate,
snooping
has
to
be
enabled
globally
and
on
specific
VLANs,
and
the
ports
within
the
VLANs
have
to
be
configured
as
trusted
or
untrusted.
On
trusted
ports,
DHCP
client
messages
are
forwarded
directly
by
the
hardware.
On
untrusted
ports,
client
messages
are
given
to
the
DHCP
snooping
application.
The
DHCP
snooping
application
builds
the
bindings
database
from
client
messages
received
on
untrusted
ports.
DHCP
snooping
creates
a
“tentative
binding”
from
DHCP
DISCOVER
and
REQUEST
messages.
Tentative
bindings
tie
a
client
to
the
port
on
which
the
message
packet
was
received.
Tentative
bindings
are
completed
when
DHCP
snooping
learns
the
client’s
IP
address
from
a
DHCP
ACK
message
on
a
trusted
port.
The
ports
on
the
switch
through
which
DHCP
servers
are
reached
must
be
configured
as
trusted
ports
so
that
packets
received
from
those
ports
will
be
forwarded
to
clients.
DCHP
packets
from
a
DHCP
server
(DHCP
OFFER,
DHCP
ACK,
DHCP
NAK)
are
dropped
if
received
on
an
untrusted
port.
port
port
‐
string
Specifies
the
port
or
ports
to
be
enabled
or
disabled
as
trusted
ports.
The
ports
can
be
physical
ports
or
LAGs
that
are
members
of
a
VLAN.
enable
|
disable
Enables
or
disables
the
specified
ports
as
trusted
ports.
Содержание SECURESTACK C3
Страница 2: ......
Страница 34: ...xxxii...
Страница 40: ...Getting Help xxxviii About This Guide...
Страница 126: ...clear license 4 6 Activating Licensed Features...
Страница 132: ...set port inlinepower 5 6 Configuring System Power and PoE...
Страница 228: ...clear port protected name 7 60 Port Configuration...
Страница 270: ...clear snmp interface 8 42 SNMP Configuration...
Страница 396: ...clear port txq 12 10 Port Priority Configuration...
Страница 414: ...ip igmp robustness 13 18 IGMP Configuration...
Страница 542: ...clear arpinspection statistics 17 32 DHCP Snooping and Dynamic ARP Inspection...
Страница 546: ...Enabling Router Configuration Modes 18 4 Preparing for Router Mode...
Страница 640: ...traceroute ipv6 21 10 IPv6 Management...
Страница 698: ...show ipv6 dhcp binding 24 20 DHCPv6 Configuration...
Страница 746: ...show ipv6 ospf virtual link 25 48 OSPFv3 Configuration...
Страница 834: ...ip access group 26 88 Authentication and Authorization Configuration...
Страница 848: ...TACACS Configuration clear tacacs interface 27 14...
Страница 866: ...sFlow Configuration show sflow agent 28 18...
Страница 872: ...Index 4...