Example 6 DHCP snooping Option 82 using the VLAN IP address
HP Switch(config)# dhcp-snooping option 82 remote-id subnet-ip
HP Switch(config)# show dhcp-snooping
DHCP Snooping Information
DHCP Snooping : Yes
Enabled Vlans : 4
Verify MAC : Yes
Option 82 untrusted policy : drop
Option 82 Insertion : Yes
Option 82 remote-id : subnet-ip
Disabling MAC address check
DHCP snooping drops DHCP packets received on untrusted ports when the check address (chaddr)
field in the DHCP header does not match the source MAC address of the packet (default behavior).
To disable this checking, use the
no
form of this command.
HP Switch(config)# dhcp-snooping verify mac
Example 7 The DHCP snooping verify MAC setting
HP Switch(config)# dhcp-snooping verify mac
HP Switch(config)# show dhcp-snooping
DHCP Snooping Information
DHCP Snooping : Yes
Enabled Vlans : 4
Verify MAC : yes
Option 82 untrusted policy : drop
Option 82 Insertion : Yes
Option 82 remote-id : subnet-ip
DHCP binding database
DHCP snooping maintains a database of up to 8192 DHCP bindings on untrusted ports. Each
binding containsf:
•
Client MAC address
•
Port number
•
VLAN identifier
•
Leased IP address
•
Lease time
The switch can be configured to store the bindings at a specific URL so they will not be lost if the
switch is rebooted. If the switch is rebooted, it reads its binding database from the specified location.
To configure this location use the following command:
12
Updates for the HP Switch Software Access Security Guide