18-13
Cisco ME 3400 EthernetAccess Switch SoftwareConfiguration Guide
78-17058-01
Chapter18 Configuring DHCP Feat ures and IP Source Guard Displaying DHCP Snooping Information
Displaying DHCP Snooping Information
To display the DHCP snooping information, use one or more of the privileged EXEC com ma nds i n
Table18-2:
Understanding IP Source Guard
Note IP source guard is supported only when the metro access or metro IP access image is running on the
switch.
IP source guard is a security feature that restricts IP traffic on nonro uted, Layer 2 interfaces by filtering
traffic based on the DHCP snooping binding database and on manually configured I P so urce bin dings.
You can use IP source guard to prevent traffic attacks caused when a host tries to use the IP address of
its neighbor.
You can enable IP source guard when DHCP snooping is enabled on an untrusted interface. After IP
source guard is enabled on an interface, the switch blocks all IP traffic received on the interface, except
for DHCP packets allowed by DHCP snooping. A port access control list (ACL) is applied to the
interface. The port ACL allows only IP traf f ic with a source IP addres s in the IP source binding t able and
denies all other traffic.
The IP source binding table has bindings that are learned by DHCP snooping or are manually configured
(static IP source bindings). An entry in this table has an IP address, its associated MAC address, and its
associated VLAN number. The switch uses the IP source binding table only w hen I P so urc e gu ar d is
enabled.
IP source guard is supported only on Layer 2 ports, including access and trunk por ts.You can configure
IP source guard with source IP address filtering or with source IP and M AC address filtering .
These sections contain this information:
Source IP Address Filtering, page 18-14
Source IP and MAC Address Filtering, page 18-14
Table18-2 Commands for Displaying DHCP Information
Command Purpose
show ip dhcp snooping Displays the DHCP snooping configuration for a switch
show ip dhcp snooping binding Displays only the dynamically configured bindings in the DHCP snooping binding
database, also referred to as a binding table.1
1. If DHCP snooping is enabled and an interface changes to the down state, the switch does not delete the manually configured bindings.
show ip dhcp snooping database Displays the DHCP snooping binding database status and statistics.
show ip source binding Display the dynamically and statically configured bindings.