Dhcpv4 Snooping - Edge-Core ECS4620-28T Quick Start Manual

28/52-port l3 stackable gigabit ethernet switch
Hide thumbs Also See for ECS4620-28T:
Table of Contents

Advertisement

Chapter 9
| General Security Measures

DHCPv4 Snooping

DHCPv4 Snooping
DHCPv4 snooping allows a switch to protect a network from rogue DHCPv4 servers
or other devices which send port-related information to a DHCPv4 server. This
information can be useful in tracking an IP address back to a physical port. This
section describes commands used to configure DHCPv4 snooping.
Table 58: DHCP Snooping Commands
Command
ip dhcp snooping
ip dhcp snooping information
option
ip dhcp snooping information
option encode no-subtype
ip dhcp snooping information
option remote-id
ip dhcp snooping information
option tr101 board-id
ip dhcp snooping information
policy
ip dhcp snooping limit rate
ip dhcp snooping verify
mac-address
ip dhcp snooping vlan
ip dhcp snooping information
option circuit-id
ip dhcp snooping trust
clear ip dhcp snooping
binding
clear ip dhcp snooping
database flash
ip dhcp snooping database
flash
show ip dhcp snooping
show ip dhcp snooping
binding
Function
Enables DHCP snooping globally
Enables or disables the use of DHCP Option 82
information, and specifies frame format for the remote-id
Disables use of sub-type and sub-length for the
CID/RID in Option 82 information
Sets the remote ID to the switch's IP address, MAC
address, arbitrary string, or TR-101 compliant node
identifier
Sets the board identifier used in Option 82 information
based on TR-101 syntax
Sets the information option policy for DHCP client
packets that include Option 82 information
Sets the maximum number of DHCP packets that can be
trapped for DHCP snooping
Verifies the client's hardware address stored in the DHCP
packet against the source MAC address in the Ethernet
header
Enables DHCP snooping on the specified VLAN
Specifies DHCP Option 82 circuit-id suboption
information
Configures the specified interface as trusted
Clears DHCP snooping binding table entries from RAM
Removes all dynamically learned snooping entries from
flash memory.
Writes all dynamically learned snooping entries to flash
memory
Shows the DHCP snooping configuration settings
Shows the DHCP snooping binding table entries
– 330 –
Mode
GC
GC
GC
GC
GC
GC
GC
GC
GC
IC
IC
PE
PE
PE
PE
PE

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents