set dhcpsnooping log-invalid
17-8 DHCP Snooping and Dynamic ARP Inspection
Parameters
Defaults
SourceMACaddressverificationisenabledbydefault.
Mode
Switchcommand,read‐write.
Usage
Whenthisverificationisenabled,theDHCPsnoopingapplica tion comparesthesourceMAC
addresscontainedinvalidclientmessageswiththeclient’shardwareaddress.Ifthereisa
mismatch,DHCPsnoopinglogstheeventanddropsthepacket.
Usetheshowdhcpsnoopingcommandtodisplaythestatus(enabledordisabled)of
sourceMAC
addressverificationforeachinterfaceinanenabledVLAN.Theshowdhcpsnoopingstatistics
commandshowstheactualnumberofMACverificationerrorsthatoccurredonuntrustedports.
Example
ThisexampledisablessourceMACaddressverificationandlogging.
B5
(rw)->set dhcpsnooping verify mac-address disable
set dhcpsnooping log-invalid
Usethiscommandtoenableordisableloggingofinva lidDHCPmessagesonports.
Syntax
set dhcpsnooping log-invalid port port-string {enable | disable}
Parameters
Defaults
Disabled.
Mode
Switchcommand,read‐write.
Usage
TheDHCPsnoopingapplicationprocessesincomingDHCPmessages.ForDHCPRELEASEand
DHCPDECLINEmessages,theapplicationcomparesthereceiveinterfaceandVLANwiththe
enable EnablesverificationofthesourceMACaddressinclientmessages
againsttheclienthardwareaddress.
disable Disablesverificationofthe sourceMACaddressinclientmessages
againstthe
clienthardwareaddress.
portport‐string Specifiestheportorportsonwhichtoenableordisableloggingof
invalidpackets.
enable|disable Enablesordisablesloggingonthespecifiedports.