Displaying Dhcp Snooping Information; Understanding Ip Source Guard - Cisco Catalyst 3750-X Software Configuration Manual

Hide thumbs Also See for Catalyst 3750-X:
Table of Contents

Advertisement

Displaying DHCP Snooping Information

Displaying DHCP Snooping Information
Table 24-2
Commands for Displaying DHCP Information
Command
show ip dhcp snooping
show ip dhcp snooping binding
show ip dhcp snooping database
show ip dhcp snooping statistics
show ip source binding
If DHCP snooping is enabled and an interface changes to the down state, the switch does not delete the
Note
statically configured bindings.

Understanding IP Source Guard

IPSG is a security feature that restricts IP traffic on nonrouted, Layer 2 interfaces by filtering traffic
based on the DHCP snooping binding database and on manually configured IP source bindings. You can
use IP source guard to prevent traffic attacks if a host tries to use the IP address of its neighbor.
You can enable IP source guard when DHCP snooping is enabled on an untrusted interface. After IPSG
is enabled on an interface, the switch blocks all IP traffic received on the interface except for DHCP
packets allowed by DHCP snooping. A port access control list (ACL) is applied to the interface. The port
ACL allows only IP traffic with a source IP address in the IP source binding table and denies all other
traffic.
The port ACL takes precedence over any router ACLs or VLAN maps that affect the same interface.
Note
The IP source binding table has bindings that are learned by DHCP snooping or are manually configured
(static IP source bindings). An entry in this table has an IP address, its associated MAC address, and its
associated VLAN number. The switch uses the IP source binding table only when IP source guard is
enabled.
IPSG is supported only on Layer 2 ports, including access and trunk ports.You can configure IPSG with
source IP address filtering or with source IP and MAC address filtering.
These sections contain this information:
Catalyst 3750-X and 3560-X Switch Software Configuration Guide
24-16
Purpose
Displays the DHCP snooping configuration for a switch
Displays only the dynamically configured bindings in the DHCP snooping binding
database, also referred to as a binding table.
Displays the DHCP snooping binding database status and statistics.
Displays the DHCP snooping statistics in summary or detail form.
Display the dynamically and statically configured bindings.
Source IP Address Filtering, page 24-17
Source IP and MAC Address Filtering, page 24-17
IP Source Guard for Static Hosts, page 24-17
Chapter 24
Configuring DHCP Features and IP Source Guard
OL-21521-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 3560-x

Table of Contents