DHCP Snooping
113
Perform following commands in global configuration mode:
Table 16-3 Configure IP-Source-Guard
Operation
Command
Description
Configure
IP-source-guard bind
table
ip-source-guard bind {ip A.B.C.D |mac
HH:HH:HH:HH:HH:HH |interface
ethernet
device-num<0>/slot-num<0-2>/port-num
<1-48>}
-
Enter interface
configuration mode
interface ethernet device/slot/port
-
Enable IP-Source-Guard
on Trust port
ip-source-guard
By default,
ip-source-guard on port is
disabled.
Caution:
IP source guard filters packets based on the following types of binding entries:
Source IP
Source IP + source MAC
Source IP + source MAC + source port
16.4 Displaying and Debugging
DHCP-Snooping
After the above configurations, you can verify the configurations by executing the show
command in any configurationw mode.
Table 16-4 Displaying and Debugging DHCP-Snooping
Operation
Command
Display DHCP-Snooping clients
show dhcp-snooping clients
Display DHCP-Snooping status in interface
show dhcp-snooping interface [ethernet
device-num<0>/slot-num<0-2>/port-num<1-48>]
Display DHCP-Snooping status in VLAN
show dhcp-snooping vlan
Display IP-Source-Guard status in interface
show ip-source-guard
Display source IP binding table of
IP-Source-Guard
show ip-source-guard bind [ip A.B.C.D]
16.5 DHCP-Snooping Configuration
Example
1.
Network requirements
As shown in Picture 1-6, the GigabitEthernet0/0/1 port of Switch is connected to DHCP
Server. A network segment containing some DHCP clients is connected to the