C
OMMAND
L
INE
I
NTERFACE
4-270
ip dhcp snooping
This command enables DHCP snooping globally. Use the no form to
restore the default setting.
Syntax
[no] ip dhcp snooping
Default Setting
Disabled
Command Mode
Global Configuration
Command Usage
• Network traffic may be disrupted when malicious DHCP messages
are received from an outside source. DHCP snooping is used to filter
DHCP messages received on an unsecure interface from outside the
network or firewall. When DHCP snooping is enabled globally by this
command, and enabled on a VLAN interface by the
ip dhcp
snooping vlan
command (page 4-272), DHCP messages received on
an untrusted interface (as specified by the
no ip dhcp snooping trust
command, page 4-273) from a device not listed in the DHCP
snooping table will be dropped.
• When enabled, DHCP messages entering an untrusted interface are
filtered based upon dynamic entries learned via DHCP snooping.
• Table entries are only learned for untrusted interfaces. Each entry
includes a MAC address, IP address, lease time, entry type
ip dhcp snooping
database flash
Displays the static host name-to-address
mapping table
GC
4-277
show ip dhcp
snooping
Displays the configuration for DNS
services
PE
4-277
show ip dhcp
snooping binding
Displays entries in the DNS cache
PE
4-278
Table 4-76 DHCP Snooping Commands
Command
Function
Mode Page
Содержание 6128L2
Страница 2: ......
Страница 21: ...CONTENTS xvii Glossary Index ...
Страница 22: ...CONTENTS xviii ...
Страница 26: ...TABLES xxii ...
Страница 40: ...INTRODUCTION 1 10 ...
Страница 54: ...INITIAL CONFIGURATION 2 14 ...
Страница 193: ...PORT CONFIGURATION 3 139 Figure 3 61 Displaying Etherlike and RMON Statistics ...
Страница 257: ...QUALITY OF SERVICE 3 203 Figure 3 90 Configuring Policy Maps ...
Страница 313: ...COMMAND GROUPS 4 13 PE Privileged Exec VC VLAN Database Configuration ...
Страница 592: ...TROUBLESHOOTING B 4 ...
Страница 605: ......