Dhcp Snooping - Dell PowerConnect 8024 User Manual

User's guide
Hide thumbs Also See for PowerConnect 8024:
Table of Contents

Advertisement

Forwarded — The number of valid ARP packets forwarded by DAI.
Dropped — The number of not valid ARP packets dropped by DAI.
Viewing Dynamic ARP Inspection Statistics With CLI Commands
For information about the CLI commands that perform this function, refer to the following chapter in
CLI Reference Guide
the
Dynamic ARP Inspection Commands
The following table summarizes the equivalent CLI commands for this feature.
Table 7-63. Dynamic ARP Inspection Command
CLI Command
show ip arp inspection statistics
clear counters ip arp inspection

DHCP Snooping

DHCP snooping is a security feature that monitors DHCP messages between a DHCP client and DHCP
servers to filter harmful DHCP messages and to build a bindings database of MAC address, IP address,
VLAN ID, and port tuples that are considered authorized. You can enable DHCP snooping globally, per-
interface, and on specific VLANs, and configure ports within the VLAN to be trusted or untrusted.
DHCP servers must be reached through trusted ports.
DHCP snooping enforces the following security rules:
DHCP packets from a DHCP server (DHCPOFFER, DHCPACK, DHCPNAK,
DHCPRELEASEQUERY) are dropped if received on an untrusted port.
DHCPRELEASE and DHCPDECLINE messages are dropped if for a MAC address in the snooping
database, but the binding's interface is other than the interface where the message was received.
On untrusted interfaces, the switch drops DHCP packets whose source MAC address does not match
the client hardware address. This feature is a configurable option.
The hardware identifies all incoming DHCP packets on ports where DHCP snooping is enabled. DHCP
snooping is enabled on a port if (a) DHCP snooping is enabled globally, and (b) the port is a member of
a VLAN where DHCP snooping is enabled. On untrusted ports, the hardware traps all incoming DHCP
packets to the CPU. On trusted ports, the hardware forwards client messages and copies server messages
to the CPU so that DHCP snooping can learn the binding.
:
Description
Displays the statistics of the ARP packets processed by Dynamic ARP
Inspection.
Resets the statistics for Dynamic ARP Inspection on all VLANs.
Configuring Switching Information
429

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Powerconnect 8024f

Table of Contents