General Security Measures

4-131

4

Example

DHCP Snooping Commands

DHCP snooping allows a switch to protect a network from rogue DHCP servers or

other devices which send port-related information to a DHCP server. This

information can be useful in tracking an IP address back to a physical port. This

section describes commands used to configure DHCP snooping.

Console#show network-access mac-address-table
---- ----------------- --------------- --------- -------------------------
Port MAC-Address RADIUS-Server Attribute Time
---- ----------------- --------------- --------- -------------------------
1/1 00-00-01-02-03-04 172.155.120.17 Static 00d06h32m50s
1/1 00-00-01-02-03-05 172.155.120.17 Dynamic 00d06h33m20s
1/1 00-00-01-02-03-06 172.155.120.17 Static 00d06h35m10s
1/3 00-00-01-02-03-07 172.155.120.17 Dynamic 00d06h34m20s
Console#

Table 4-42 DHCP Snooping Commands

Command Function Mode Page
ip dhcp snooping Enables DHCP snooping globally GC 4-132
ip dhcp snooping vlan Enables DHCP snooping on the specified VLAN GC 4-133
ip dhcp snooping trust Configures the specified interface as trusted IC 4-134
ip dhcp snooping verify
mac-address
Verifies the client’s hardware address stored in the DHCP
packet against the source MAC address in the Ethernet header
GC 4-135
ip dhcp snooping
information option
Enables or disables DHCP Option 82 information relay GC 4-136
ip dhcp snooping
information policy
Sets the information option policy for DHCP client packets that
include Option 82 information
GC 4-137
show ip dhcp snooping Shows the DHCP snooping configuration settings PE 4-138
show ip dhcp snooping
binding
Shows the DHCP snooping binding table entries PE 4-138