Displaying And Maintaining Dhcp Snooping Configuration - 3Com 5500-EI PWR Install Manual

Hide thumbs Also See for 5500-EI PWR:
Table of Contents

Advertisement

For details about 802.1x authentication, refer to 802.1x and System Guard Operation.
You are not recommended to configure IP filtering on the ports of an aggregation group.
Enable DHCP snooping and specify trusted ports on the switch before configuring IP filtering based
on the DHCP-snooping table.
To implement IP filtering based on IP-to-MAC bindings of authenticated 802.1x clients, the device
assigns an ACL to each of such bindings. If an ACL fails to be assigned to a binding, the
corresponding authenticated 802.1x client is forced to go offline.
IP filtering based on IP-to-MAC bindings of authenticated 802.1x clients requires to be associated
with 802.1x based on MAC address authentication, and requires 802.1x clients to provide IP
addresses; otherwise, the IP addresses of 802.1x clients cannot be obtained. To ensure IP
addresses of DHCP clients can be updated for corresponding IP-to-MAC entries, you are
recommended to enable 802.1x authentication handshake function; otherwise, you need to disable
802.1x authentication triggered by DHCP, ensuring normal receiving and forwarding of multicast
authentication packets.
To create a static binding after IP filtering is enabled with the mac-address keyword specified on a
port, the mac-address argument must be specified; otherwise, the packets sent from this IP
address cannot pass the IP filtering.
A static entry has a higher priority than the dynamic DHCP snooping entry that has the same IP
address as the static one. That is, if the static entry is configured after the dynamic entry is
recorded, the static entry overwrites the dynamic entry; if the static entry is configured before
DHCP snooping is enabled, no DHCP client can obtain the IP address of the static entry, that is, the
dynamic DHCP snooping entry cannot be generated.
The VLAN ID of the IP static binding configured on a port is the VLAN ID of the port.

Displaying and Maintaining DHCP Snooping Configuration

Display the user IP-to-MAC address
mapping entries recorded by the DHCP
snooping function
Display the (enabled/disabled) state of
the DHCP snooping function and the
trusted ports
Display the IP static binding table
Remove DHCP snooping entries
To do...
Use the command...
display dhcp-snooping [ unit unit-id ]
display dhcp-snooping trust
display ip source static binding [ vlan
vlan-id | interface interface-type
interface-number ]
reset dhcp-snooping [ ip-address ]
4-10
Remarks
Available in
any view
Available in
user view

Advertisement

Table of Contents
loading

This manual is also suitable for:

5500-ei series

Table of Contents