Cisco WS-C6506 Software Manual page 883

Catalyst 6500 series switch
Hide thumbs Also See for WS-C6506:
Table of Contents

Advertisement

Chapter 33
Configuring DHCP Snooping and IP Source Guard
Enter the show command to display the security-acl mode:
Console> (enable) show port security-acl 1/2
Port
config
----- -------------- -------------- ----------------------
1/2
Config:
Port
----- -------------------------------- ----
1/2
Runtime:
Port
----- -------------------------------- ----
1/2
dhcp-snooping:
Port
-----
1/2
Port
-----
1/2
Enter the show command to verify the mapping:
Console> (enable) show security acl map config all
ACL Name
-------------------------------- ---- ----------------
dhcp
dhcp
The following example shows how to enable DHCP snooping in port-based mode with an external router
configuration. DHCP snooping ACL is mapped to the host and the DHCP server port.
Both the host and server ports are in port-based security ACL mode.
Note
Console> (enable) set port security-acl 1/2 port-based
Warning: Vlan-based ACL features will be disabled on ports 1/2
ACL interface is set to port-based mode for port(s) 1/2.
Console> (enable) set port security-acl 5/2 port-based
Warning: Vlan-based ACL features will be disabled on ports 5/2
ACL interface is set to port-based mode for port(s) 5/2.
Console> (enable) set security acl map dhcp 1/2
Mapping in progress.
ACL dhcp successfully mapped to port(s) 1/2
Console> (enable) set security acl map dhcp 5/2
Mapping in progress.
ACL dhcp successfully mapped to port(s) 5/2
Enter the show command to display the security ACL mode:
Console> (enable) show port security-acl 1/2
Port
config
----- -------------- -------------- ----------------------
1/2
OL-8978-04
Interface Type Interface Type Interface Merge Status
runtime
port-based
port-based
ACL name
dhcp
ACL name
dhcp
Trust
Source-Guard
-----------
------------
untrusted
disabled
Binding Limit
------------------
32
Interface Type Interface Type Interface Merge Status
runtime
port-based
port-based
runtime
not applicable
Type
IP
Type
IP
Source-Guarded IP Addresses
---------------------------
No. of Existing Bindings
------------------------
0
Type Ports/Vlans
IP
16
IP
1/2
runtime
not applicable
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
Configuring DHCP Snooping on a VLAN
33-9

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6506Catalyst 6509Catalyst 6513

Table of Contents