Enabling DHCP snooping
To enable DHCP snooping globally, enter this command:
HP Switch(config)# dhcp-snooping
To disable DHCP snooping, use the
no
form of the command.
Syntax:
[
no
]
dhcp-snooping
[
authorized-server | database | option | trust |
verify | vlan
]
Detail
Task
Parameter
Maximum: 20 authorized
servers.
Enters the IP address of a trusted DHCP server.
If no authorized servers are configured, all DHCP
server addresses are considered valid.
authorized
server
The maximum number of
characters for the URL is 63.
To configure a location for the lease database,
enter a URL in the format
tftp://ip-ddr/ascii-string
database
The default is
yes
, add relay
information.
Adds relay information option (Option 82) to
DHCP client packets that are being forwarded
to trusted ports.
option
Default:
untrusted
Configures trusted ports. Only server packets
received on trusted ports are forwarded.
trust
Default:
Yes
Enables DHCP packet validation. The DHCP
client hardware address field and the source
verify
MAC address must be the same for packets
received on untrusted ports or the packet is
dropped.
Default:
No
Enables DHCP snooping on a vlan. DHCP
snooping must be enabled already.
vlan
To display the DHCP snooping configuration, enter this command:
HP Switch(config)# show dhcp-snooping
Example 1 DHCP snooping command output
HP Switch(config)# show dhcp-snooping
DHCP Snooping Information
DHCP Snooping : Yes
Enabled Vlans :
Verify MAC : Yes
Option 82 untrusted policy : drop
Option 82 Insertion : Yes
Option 82 remote-id : mac
Store lease database : Not configured
Port Trust
----- -----
5 No
6 No
7 No
To display statistics about the DHCP snooping process, enter this command:
HP Switch(config)# show dhcp-snooping stats
8
Updates for the HP Switch Software Access Security Guide