Chapter 8
| General Security Measures
DHCP Snooping
– 242 –
DHCP Snooping
DHCP snooping allows a switch to protect a network from rogue DHCP servers or
other devices which send port-related information to a DHCP server. This
information can be useful in tracking an IP address back to a physical port. This
section describes commands used to configure DHCP snooping.
ip dhcp snooping
This command enables DHCP snooping globally. Use the
no
form to restore the
default setting.
Syntax
[
no
]
ip dhcp snooping
Default Setting
Disabled
Command Mode
Global Configuration
Command Usage
◆
Network traffic may be disrupted when malicious DHCP messages are received
from an outside source. DHCP snooping is used to filter DHCP messages
received on an unsecure interface from outside the network or fire wall. When
DHCP snooping is enabled globally by this command, and enabled on a VLAN
interface by the
ip dhcp snooping vlan
command, DHCP messages received on
Table 50: DHCP Snooping Commands
Command
Function
Mode
ip dhcp snooping
Enables DHCP snooping globally
GC
ip dhcp snooping information
option
Enables or disables DHCP Option 82 information relay
GC
ip dhcp snooping information
policy
Sets the information option policy for DHCP client
packets that include Option 82 information
GC
ip dhcp snooping verify
mac-address
Verifies the client’s hardware address stored in the DHCP
packet against the source MAC address in the Ethernet
header
GC
ip dhcp snooping vlan
Enables DHCP snooping on the specified VLAN
GC
ip dhcp snooping trust
Configures the specified interface as trusted
IC
clear ip dhcp snooping
database flash
Removes all dynamically learned snooping entries from
flash memory.
PE
ip dhcp snooping database
flash
Writes all dynamically learned snooping entries to flash
memory
PE
show ip dhcp snooping
Shows the DHCP snooping configuration settings
PE
show ip dhcp snooping
binding
Shows the DHCP snooping binding table entries
PE
Содержание EX-3524
Страница 2: ......
Страница 28: ...Figures 28 ...
Страница 34: ...Section I Getting Started 34 ...
Страница 58: ...Chapter 1 Initial Switch Configuration Setting the System Clock 58 ...
Страница 72: ...Chapter 2 Using the Command Line Interface CLI Command Groups 72 ...
Страница 156: ...Chapter 5 SNMP Commands Notification Log Commands 156 ...
Страница 164: ...Chapter 6 Remote Monitoring Commands 164 ...
Страница 218: ...Chapter 7 Authentication Commands Management IP Filter 218 ...
Страница 268: ...Chapter 8 General Security Measures Port based Traffic Segmentation 268 ...
Страница 292: ...Chapter 9 Access Control Lists ACL Information 292 ...
Страница 312: ...Chapter 10 Interface Commands Power Savings 312 ...
Страница 324: ...Chapter 11 Link Aggregation Commands Trunk Status Display Commands 324 ...
Страница 366: ...Chapter 15 Address Table Commands 366 ...
Страница 428: ...Chapter 17 VLAN Commands Configuring Voice VLANs 428 ...
Страница 572: ...Chapter 25 IP Interface Commands IPv6 Interface 572 ...
Страница 578: ...Section I Appendices 578 ...
Страница 594: ...Appendix C Customer Support Manuals 594 ...