EasyManua.ls Logo

Dasan V5808 - Displaying DHCP Snooping Configuration; IP Source Guard

Dasan V5808
814 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
User Manual UMN:CLI
V5808
353
To specify a DHCP server default option, use the following command.
Command
Mode
Description
ip dhcp snooping default-option
code <1-254> format NAME
Global
Specifies a snooping default option format for a switch.
NAME: DHCP option format name
ip dhcp snooping default-option
code <1-254> policy <keep |
replace>
Configures a policy against DHCP option belonging to
a DHCP message (default: replace)
keep: forwards a DHCP message to DHCP server
without any modification.
replace: deletes the DHCP messages option and adds
the snooping default option if both of them are same.
However, if they are different each other, replace
option just adds the snooping default option.
no ip dhcp snooping default-
option code <1-254>
Removes the DHCP snooping default option for a
given port.
8.5.7.12 Displaying DHCP Snooping Configuration
To display DHCP snooping table, use the following command.
Command
Mode
Description
show ip dhcp snooping
Enable
Global
Shows a DHCP snooping configuration.
show ip dhcp snooping binding
[port PORTS]
Shows DHCP snooping binding entries.
PORTS: port number to use
show ip dhcp snooping binding
vlan VLANS
Shows DHCP snooping binding vlan.
VLANS: vlan id to use
show ip dhcp snooping lease-
time
Shows DHCP snooping lease time.
show ip dhcp snooping
statistics [port PORTS]
Shows DHCP snooping statistics.
To clear DHCP snooping statistics of the DHCP server, use the following command.
Command
Mode
Description
clear ip dhcp snooping
statistics [port PORTS]
Enable
Global
Clears DHCP snooping statistics.
8.5.8 IP Source Guard
IP source guard is similar to DHCP snooping. This function is used on DHCP snooping
untrusted Layer 2 port. Basically, except for DHCP packets that are allowed by DHCP
snooping process, all IP traffic comes into a port is blocked. If an authorized IP address
from the DHCP server is assigned to a DHCP client, or if a static IP source binding is
configured, the IP source guard restricts the IP traffic of client to those source IP
addresses configured in the binding; any IP traffic with a source IP address other than
that in the IP source binding will be filtered out. This filtering limits a host's ability to attack

Table of Contents