DHCP Snooping Commands
325
12
DHCP Snooping Commands
DHCP Snooping is a security feature that monitors DHCP messages between
DHCP clients and DHCP server to filter harmful DHCP messages and build
a bindings database of {MAC address, IP address, VLAN ID, interface} tuples
that are considered authorized.
The DHCP snooping application processes incoming DHCP messages. For
DHCPRELEASE and DHCPDECLINE messages, the application compares
the receive interface and VLAN with the client's interface and VLAN in the
bindings database. If the interfaces do not match, the application logs the
event and drops the message. For valid client messages, DHCP snooping
compares the source MAC address to the DHCP client hardware address.
When there is a mismatch, DHCP snooping logs and drops the packet.
DHCP Snooping forwards valid client messages on trusted members within
the VLAN. If DHCP Relay and/or DHCP Server coexist with DHCP
Snooping, the DHCP client message is sent to the DHCP Relay or/and
DHCP Server for further processing.
The DHCP Snooping application uses DHCP messages to build and
maintain the binding's database. The binding's database only includes data
for clients on untrusted ports. DHCP Snooping creates a tentative binding
from DHCP DISCOVER and REQUEST messages. Tentative bindings tie a
client to a port (the port where the DHCP client message was received).
Tentative bindings are completed when DHCP Snooping learns the client's IP
address from a DHCP ACK message on a trusted port. DHCP Snooping
removes bindings in response to DECLINE, RELEASE, and NACK messages.
The DHCP Snooping application ignores the ACK messages as a reply to the
DHCP Inform messages received on trusted ports. The network administrator
can enter static bindings into the binding database.
IP Source Guard and Dynamic ARP Inspection use the DHCP Snooping
bindings database for the validation of IP and ARP packets.
Commands in this Chapter
This chapter explains the following commands:
2CSPC4.XModular-SWUM200.book Page 325 Thursday, March 10, 2011 11:18 AM
Summary of Contents for PowerEdge M420
Page 161: ...Command Groups 161 ...
Page 162: ...162 Command Groups ...
Page 216: ...216 Layer 2 Commands ...
Page 290: ...290 Auto VoIP Commands ...
Page 310: ...310 Data Center Bridging Commands ...
Page 316: ...316 DHCP Layer 2 Relay Commands Example console config dhcp l2relay vlan 10 340 345 ...
Page 324: ...324 DHCP Management Interface Commands ...
Page 340: ...340 DHCP Snooping Commands ...
Page 354: ...354 Dynamic ARP Inspection Commands ...
Page 405: ...Ethernet Configuration Commands 405 Name test ...
Page 406: ...406 Ethernet Configuration Commands ...
Page 426: ...426 Ethernet CFM Commands ...
Page 486: ...486 IPv6 Access List Commands ...
Page 497: ...IPv6 MLD Snooping Commands 497 Vlan Ipv6 Address Ports ...
Page 498: ...498 IPv6 MLD Snooping Commands ...
Page 512: ...512 IP Source Guard Commands ...
Page 524: ...524 iSCSI Optimization Commands ...
Page 532: ...532 Link Dependency Commands ...
Page 572: ...572 Port Aggregator Commands ...
Page 756: ...756 VLAN Commands ...
Page 762: ...762 Voice VLAN Commands ...
Page 796: ...796 802 1x Commands ...
Page 798: ...798 Layer 3 Commands ...
Page 842: ...842 DHCP Server and Relay Agent Commands ...
Page 868: ...868 DVMRP Commands ...
Page 888: ...888 IGMP Commands ...
Page 896: ...896 IGMP Proxy Commands ...
Page 938: ...938 IP Routing Commands ...
Page 1012: ...1012 IPv6 Routing Commands ...
Page 1016: ...1016 Loopback Interface Commands ...
Page 1048: ...1048 Multicast Commands ...
Page 1064: ...1064 IPv6 Multicast Commands RP Address 3001 1 origin BSR ...
Page 1142: ...1142 OSPF Commands ...
Page 1202: ...1202 OSPFv3 Commands ...
Page 1212: ...1212 Router Discovery Protocol Commands ...
Page 1228: ...1228 Routing Information Protocol Commands ...
Page 1260: ...1260 Virtual Router Redundancy Protocol Commands ...
Page 1262: ...1260 Utility Commands ...
Page 1272: ...1270 Auto Install Commands ...
Page 1306: ...1304 Captive Portal Commands ...
Page 1316: ...1314 CLI Macro Commands ...
Page 1334: ...1332 Clock Commands ...
Page 1340: ...1338 Command Line Configuration Scripting Commands ...
Page 1362: ...1360 Configuration and Image File Commands ...
Page 1363: ...Configuration and Image File Commands 1361 ...
Page 1364: ...1362 Configuration and Image File Commands ...
Page 1412: ...1408 Password Management Commands ...
Page 1436: ...1432 RMON Commands ...
Page 1476: ...1472 Sflow Commands ...
Page 1536: ...1532 Syslog Commands ...
Page 1602: ...1598 Telnet Server Commands ...
Page 1604: ...1600 Terminal Length Commands ...
Page 1618: ...1614 User Interface Commands ...
Page 1638: ...1634 Web Server Commands ...
Page 1680: ...1676 Appendix A List of Commands ...
Page 1681: ......
Page 1682: ...www dell com support dell com Printed in the U S A ...