© Copyright Lenovo 2017 Chapter 1: Switch Administration 41
SYSLOG Server
Duringswitchstartup,iftheswitchfailstogettheconfigurationfile, amessagecan
berecordedintheSYSLOGserver.
TheCN4093supportsrequestingofaSYSLOGserverIPaddressfromtheDHCP
serverasdescribedinRFC2132,option7.DHCPSYSLOGserverrequestoptionis
enabledbydefault.
Manually
configuredSYSLOGservertakespriorityoverDHCPSYSLOGserver.
UptotwoSYSLOGserveraddressesreceivedfromtheDHCPservercanbeused.
TheSYSLOGservercanbelearntoveramanagementportoradataport.
Usetheshow loggingcommandtoviewtheSYSLOGserveraddress.
DHCPSYSLOGserveraddress
optioncanbeenabled/disabledusingthefollowing
command:
DHCP Snooping
DHCPsnoopingprovidessecuritybyfilteringuntrustedDHCPpacketsandby
buildingandmaintainingaDHCPsnoopingbindingtable.Thisfeatureis
applicableonlytoIPv4andonlyworksinnon‐stackingmode.
Anuntrustedinterfaceisaportthatisconfiguredtoreceivepacketsfromoutside
thenetworkorfirewall.
Atrustedinterfacereceivespacketsonlyfromwithinthe
network.Bydefault,allDHCPportsareuntrusted.
TheDHCPsnoopingbindingtablecontainstheMACaddress,IPaddress,lease
time,bindingtype,VLANnumber,andportnumberthatcorrespondtothelocal
untrustedinterfaceontheswitch; itdoesnotcontain
informationregardinghosts
interconnectedwithatrustedinterface.
Bydefault,DHCPsnoopingisdisabledonallVLANs.YoucanenableDHCP
snoopingononeormoreVLANs.YoumustenableDHCPsnoopingglobally.To
enablethisfeature,enterthefollowingcommands:
Note: WhenyoumakeaDHCPreleasefromaclient,the
switchdoesnotforward
theUnicastDHCPreleasepackettotheserver,theentryisnotremovedfromthe
DHCPsnoopingbindingtable,andthecounterforReceivedRequestpacketsdoes
notincreaseeventhoughthereleasepacketdoesarriveattheswitch.
IfyouwanttheDHCP Renew/Releasepacketto
be forwardedtotheserverandthe
correspondingentryremovedfromtheDHCPsnoopingbindingtable,configure
aninterfaceIPaddresswiththesamsubnetinthesameVLAN.
CN 4093(config)# [no] system dhcp syslog
CN 4093(config)# ip dhcp snooping vlan <vlannumber(s)>
CN 4093(config)# ip dhcp snooping