DXS-3600 Series Layer 3 Managed 10Gigabit Ethernet Switch CLI Reference Guide
372
23-4 ip dhcp snooping server-screen
This command is used to enable or disable DHCP server screening.
ip dhcp snooping server-screen [SERVER-IP-ADDRESS [profile PROFILE-NAME]]
no ip dhcp snooping server-screen [SERVER-IP-ADDRESS]
Parameters
SERVER-IP-ADDRESS
(Optional) Specifies the trust DHCP sever IP address.
profile PROFILE-NAME
(Optional) Specifies the profile with the client MAC address list for the
DHCP sever.
Default
None.
Command Mode
Interface Configuration Mode.
Command Default Level
Level: 12.
Usage Guideline
The DHCP server screening function is used to filter the DHCP server packets on the specific interface
and receive the trust packets from the specific source. This feature can make a protected network usable
when a malicious host sends DHCP server packets.
If the server IP address is not specified, it will enabled or disabled the DHCP server screen on the
interface. By default, the DHCP server screen is disabled on all interfaces. If enabled, the DHCP server
screen, on a specific interface, will filter all DHCP server packets from the interface and only forward
trusted server packets.
If a server screen entry is defined with a profile that contains a client MAC address, then the server
message with the server IP address and the client addresses contained in the profile is forwarded.
If an entry is defined without the client’s MAC address, then the server message with the specified server
IP address will be forwarded. Each server can only have one corresponding entry in the table.
If the entry is defined with a profile but the entry does not exist, then messages with the server IP
specified by the entry are not forwarded.
Example
This example shows how to configure a DHCP server screen profile named “campus-profile” and
associate it with a DHCP server screen entry for port Ethernet 1/0/3.
Switch# configure terminal
Switch(config)# dhcp-server-screen profile campus-profile
Switch(config-dhcp-server-screen)# based-on hardware-address 00-08-01-02-03-04
Switch(config-dhcp-server-screen)# based-on hardware-address 00-08-01-03-00-01
Switch(config-dhcp-server-screen)# exit
Switch(config)# interface ethernet 1/0/3
Switch(config-if)# ip dhcp snooping server-screen 10.1.1.2 profile campus-profile
Switch(config-if)#
Summary of Contents for DXS-3600 Series
Page 1: ......
Page 423: ...DXS 3600 Series Layer 3 Managed 10Gigabit Ethernet Switch CLI Reference Guide 418 ...
Page 548: ...DXS 3600 Series Layer 3 Managed 10Gigabit Ethernet Switch CLI Reference Guide 543 ...
Page 673: ...DXS 3600 Series Layer 3 Managed 10Gigabit Ethernet Switch CLI Reference Guide 668 ...
Page 712: ...DXS 3600 Series Layer 3 Managed 10Gigabit Ethernet Switch CLI Reference Guide 707 Switch ...
Page 845: ...DXS 3600 Series Layer 3 Managed 10Gigabit Ethernet Switch CLI Reference Guide 840 ...
Page 884: ...DXS 3600 Series Layer 3 Managed 10Gigabit Ethernet Switch CLI Reference Guide 879 ...
Page 1152: ...DXS 3600 Series Layer 3 Managed 10Gigabit Ethernet Switch CLI Reference Guide 1147 ...