General Security Measures
4-183
4
•
Additional considerations when the switch itself is a DHCP client
– The port(s)
through which it submits a client request to the DHCP server must be
configured as trusted.
Example
This example sets port 5 to untrusted.
Related Commands
ip dhcp snooping (4-180)
ip dhcp snooping vlan (4-181)
This command verifies the client’s hardware address stored in the DHCP packet
against the source MAC address in the Ethernet header. Use the
no
form to disable
this function.
Syntax
[
no
]
ip dhcp snooping verify mac-address
Default Setting
Enabled
Command Mode
Global Configuration
Command Usage
If MAC address verification is enabled, and the source MAC address in the
Ethernet header of the packet is not same as the client’s hardware address in
the DHCP packet, the packet is dropped.
Example
This example enables MAC address verification.
Related Commands
ip dhcp snooping (4-180)
ip dhcp snooping vlan (4-181)
ip dhcp snooping trust (4-182)
Содержание 6152PL2 FICHE
Страница 2: ......
Страница 6: ...vi ...
Страница 8: ...viii ...
Страница 32: ...Tables xxxii ...
Страница 38: ...Figures xxxviii ...
Страница 56: ...Initial Configuration 2 10 2 ...
Страница 378: ...Configuring the Switch 3 322 3 ...
Страница 651: ...Address Table Commands 4 273 4 Example Console show mac address table aging time Aging time 100 sec Console ...
Страница 817: ......
Страница 818: ...SMC6128PL2 SMC6152PL2 149100000007A R01 ...