set dhcpsnooping log-invalid
17-8 DHCP Snooping and Dynamic ARP Inspection
Parameters
Defaults
SourceMACaddressverificationisenabledbydefault.
Mode
Switchcommand,readwrite.
Usage
Whenthisverification isenabled,theDHCPsnoopingapplicationcomparesthesourceMAC
addresscontainedinvalidclientmessageswiththeclient’shardwareaddress.Ifthereisa
mismatch,DHCPsnoopinglogstheeventanddropsthepacket.
Usetheshowdhcpsnoopingcommandtodisplaythestatus(enabledordisabled)ofsourceMAC
addressverificationforeachinterfaceinanenabledVLAN.Theshowdhcpsnoopingstatistics
commandshowstheactualnumberofMACverificationerrorsthatoccurredonuntrustedports.
Example
ThisexampledisablessourceMACaddressverification andlogging.
C3(rw)->set dhcpsnooping verify mac-address disable
set dhcpsnooping log-invalid
UsethiscommandtoenableordisableloggingofinvalidDHCPmessagesonports.
Syntax
set dhcpsnooping log-invalid port port-string {enable | disable}
Parameters
Defaults
Disabled.
Mode
Switchcommand,readwrite.
Usage
TheDHCPsnoopingapplicationprocessesincomingDHCPmessages.ForDHCPRELEASEand
DHCPDECLINEmessages,theapplicationcomparesthereceiveinterfaceandVLANwiththe
enable Enablesverification ofthesourceMACaddressinclientmessages
againsttheclienthardwareaddress.
disable Disablesverificationofthesou rceMACaddressinclientmessages
againsttheclienthardwareaddress.
portportstring Specifiestheportorportsonwhichtoenableordisableloggingof
invalidpackets.
enable|disable Enablesordisablesloggingonthespecifiedports.