Example
This example configures port ge.1.1 as a trusted port.
C2
(rw)->set dhcpsnooping trust port ge.1.1 enable
set dhcpsnooping binding
Use this command to add a static DHCP binding to the DHCP snooping database.
Syntax
set dhcpsnooping binding mac-address vlan vlan-id ipaddr port port-string
Parameters
mac‐address
vlan vlan‐id
ipaddr
port port‐string
Defaults
None.
Mode
Switch command, read‐write.
Usage
When enabled globally and on VLANs, DHCP snooping builds its bindings database from DHCP
client messages received on untrusted ports. Such entries in the database are dynamic entries
which will be removed in response to valid DECLINE, RELEASE, and NACK messages or when
the absolute lease time of the entry expires.
You can add static entries to the bindings database with this command.
Example
This example creates a static entry, associating MAC address 00:01:02:33:44:55 with IP address
192.168.10.10 and VLAN 10, port ge.1.1.
C2
(rw)->set dhcpsnooping binding 00:01:02:33:44:55 vlan 10 192.168.10.10 port
ge.1.1
set dhcpsnooping verify
Use this command to enable or disable DHCP snooping to filter on source MAC address.
Syntax
set dhcpsnooping verify mac-address {enable | disable}
Specifies the MAC address of the binding entry.
Specifies the VLAN of the binding entry.
Specifies the IP address of the binding entry.
Specifies the port of the binding entry.
set dhcpsnooping binding
SecureStack C2 Configuration Guide 17-7