MAC Address
-----------------
00:02:B3:06:60:80
00:0F:FE:00:13:04
show dhcpsnooping statistics
Use this command to display DHCP snooping statistics for untrusted ports.
Syntax
show dhcpsnooping statistics
Parameters
None.
Defaults
None.
Mode
Switch command, read‐write.
Usage
The DHCP snooping application processes incoming DHCP messages on enabled untrusted
interfaces. For DHCP RELEASE and DHCP DECLINE messages, the application compares the
receive interface and VLAN with the clientʹs interface and VLAN in the bindings database. If the
interfaces do not match, the application logs the event (if logging of invalid messages is enabled)
and drops the message. If source MAC verification is enabled, for valid client messages, DHCP
snooping compares the source MAC address to the DHCP client hardware address. Where there is
a mismatch, DHCP snooping logs and drops the packet.
This command displays, for each enabled untrusted interface, the number of source MAC
verification failures and client interface mismatches that occurred since the last time these
statistics were cleared.
Since DHCP servers should not be connected through an untrusted port, the DHCP snooping
application will drop incoming DHCP server messages on untrusted interfaces and increment a
counter that is displayed with this command.
Example
This example shows the output of the show dhcpsnooping statistics command.
C3(su)->show dhcpsnooping statistics
Interface
-----------
ge.1.48
lag.0.1
IP Address
---------------
192.168.10.10
192.168.20.1
MAC Verify
Client Ifc
Failures
Mismatch
----------
----------
0
0
VLAN
Interface
----
-----------
-------
3
ge.1.1
5
ge.1.30
DHCP Server
Msgs Rec'd
-----------
0
0
0
0
SecureStack C3 Configuration Guide 17-13
show dhcpsnooping statistics
Type
Lease (min)
-----------
STATIC
DYNAMIC
1440
Need help?
Do you have a question about the SECURESTACK C3 and is the answer not in the manual?
Questions and answers