show dhcpsnooping statistics

MAC Address

IP Address

VLAN

Interface

Type

Lease (min)

-----------------

--------------- ---- ----------- ------- -----------

00:02:B3:06:60:80

192.168.10.10

3

ge.1.1

STATIC

 

00:0F:FE:00:13:04

192.168.20.1

5

ge.1.30

DYNAMIC

1440

show dhcpsnooping statistics

Use this command to display DHCP snooping statistics for untrusted ports.

Syntax

show dhcpsnooping statistics

Parameters

None.

Defaults

None.

Mode

Switch command, read‐write.

Usage

The DHCP snooping application processes incoming DHCP messages on enabled untrusted interfaces. For DHCP RELEASE and DHCP DECLINE messages, the application compares the receive interface and VLAN with the clientʹs interface and VLAN in the bindings database. If the interfaces do not match, the application logs the event (if logging of invalid messages is enabled) and drops the message. If source MAC verification is enabled, for valid client messages, DHCP snooping compares the source MAC address to the DHCP client hardware address. Where there is a mismatch, DHCP snooping logs and drops the packet.

This command displays, for each enabled untrusted interface, the number of source MAC verification failures and client interface mismatches that occurred since the last time these statistics were cleared.

Since DHCP servers should not be connected through an untrusted port, the DHCP snooping application will drop incoming DHCP server messages on untrusted interfaces and increment a counter that is displayed with this command.

Example

This example shows the output of the show dhcpsnooping statistics command.

C3(su)->show dhcpsnooping statistics

 

Interface

MAC Verify

Client Ifc

DHCP Server

 

Failures

Mismatch

Msgs Rec'd

-----------

----------

----------

-----------

ge.1.48

0

0

0

lag.0.1

0

0

0

SecureStack C3 Configuration Guide 17-13

Page 523
Image 523
Enterasys Networks 9034313-07 manual Show dhcpsnooping statistics