Drop Dhcp Packets On Snooped Vlans Only; Dynamic Arp Inspection - Dell Z9000 Configuration Manual

10/25/40/50/100gbe throughput
Hide thumbs Also See for Z9000:
Table of Contents

Advertisement

Example of the show ip dhcp snooping Command
View the DHCP snooping statistics with the show ip dhcp snooping command.
Dell#show ip dhcp snooping
IP DHCP Snooping
IP DHCP Snooping Mac Verification
IP DHCP Relay Information-option
IP DHCP Relay Trust Downstream
Database write-delay (In minutes)
DHCP packets information
Relay Information-option packets
Relay Trust downstream packets
Snooping packets
Packets received on snooping disabled L3 Ports
Snooping packets processed on L2 vlans
DHCP Binding File Details
Invalid File
Invalid Binding Entry
Binding Entry lease expired
List of Trust Ports
List of DHCP Snooping Enabled Vlans
List of DAI Trust ports

Drop DHCP Packets on Snooped VLANs Only

Binding table entries are deleted when a lease expires or the relay agent encounters a DHCPRELEASE.
Line cards maintain a list of snooped VLANs. When the binding table fills, DHCP packets are dropped only
on snooped VLANs, while such packets are forwarded across non-snooped VLANs. Because DHCP
packets are dropped, no new IP address assignments are made. However, DHCP release and decline
packets are allowed so that the DHCP snooping table can decrease in size. After the table usage falls
below the maximum limit of 4000 entries, new IP address assignments are allowed.
To view the number of entries in the table, use the show ip dhcp snooping binding command. This
output displays the snooping binding table created using the ACK packets from the trusted port.
Dell#show ip dhcp snooping binding
Codes : S - Static D - Dynamic
IP Address
MAC Address
================================================================
10.1.1.251
00:00:4d:57:f2:50
10.1.1.252
00:00:4d:57:e6:f6
10.1.1.253
00:00:4d:57:f8:e8
10.1.1.254
00:00:4d:69:e8:f2
Total number of Entries in the table : 4

Dynamic ARP Inspection

Dynamic address resolution protocol (ARP) inspection prevents ARP spoofing by forwarding only ARP
frames that have been validated against the DHCP binding table.
ARP is a stateless protocol that provides no authentication mechanism. Network devices accept ARP
requests and replies from any device. ARP replies are accepted even when no request was sent. If a client
266
: Enabled.
: Disabled.
: Disabled.
: Disabled.
: 0
: 0
: 0
: 0
: 0
: 142
: 0
: 0
: 0
:Te 0/49
:Vl 10
:Te 0/49
Expires(Sec) Type VLAN
172800
D
172800
D
172740
D
172740
D
Dynamic Host Configuration Protocol (DHCP)
Interface
Vl 10
Te 0/2
Vl 10
Te 0/1
Vl 10
Te 0/3
Vl 10
Te 0/50

Advertisement

Table of Contents
loading

Table of Contents