Enabling DHCP Snooping (CLI Procedure)
DHCP snooping allows the switch to monitor and control DHCP messages received from
untrusted devices connected to the EX Series switch. It builds and maintains a database
of valid IP-address/MAC-address (IP-MAC) bindings called the DHCP snooping database.
You configure DHCP snooping for each VLAN, not for each interface (port). By default,
DHCP snooping is disabled for all VLANs.
To enable DHCP snooping on a VLAN or all VLANs by using the CLI:
•
On a specific VLAN (here, the VLAN is
default
):
[edit ethernet-switching-options secure-access port]
user@switch#
set vlan default
examine-dhcp
•
On all VLANs:
[edit ethernet-switching-options secure-access port]
user@switch#
set vlan all examine-dhcp
TIP:
By default, the IP-MAC bindings are lost when the switch is rebooted
and DHCP clients (the network devices, or hosts) must reacquire bindings.
However, you can configure the bindings to persist by setting the
dhcp-snooping-file
statement to store the database file either locally or
remotely.
TIP:
For private VLANs (PVLANs), enable DHCP snooping on the primary
VLAN. If you enable DHCP snooping only on a community VLAN, DHCP
messages coming from PVLAN trunk ports are not snooped.
Related
Documentation
Enabling DHCP Snooping (J-Web Procedure) on page 2911
•
•
Example: Configuring Port Security, with DHCP Snooping, DAI, MAC Limiting, and MAC
Move Limiting, on an EX Series Switch on page 2849
•
Example: Configuring DHCP Snooping, DAI , and MAC Limiting on an EX Series Switch
with Access to a DHCP Server Through a Second Switch on page 2873
•
Example: Configuring DHCP Snooping and DAI to Protect the Switch from ARP Spoofing
Attacks on page 2866
•
Verifying That DHCP Snooping Is Working Correctly on page 2934
•
Monitoring Port Security on page 2933
•
Understanding DHCP Snooping for Port Security on EX Series Switches on page 2829
Copyright © 2010, Juniper Networks, Inc.
2910
Complete Software Guide for Junos
®
OS for EX Series Ethernet Switches, Release 10.3
Summary of Contents for JUNOS OS 10.3 - SOFTWARE
Page 325: ...CHAPTER 17 Operational Mode Commands for System Setup 229 Copyright 2010 Juniper Networks Inc ...
Page 1323: ...CHAPTER 56 Operational Mode Commands for Interfaces 1227 Copyright 2010 Juniper Networks Inc ...
Page 2841: ...CHAPTER 86 Operational Commands for 802 1X 2745 Copyright 2010 Juniper Networks Inc ...
Page 3367: ...CHAPTER 113 Operational Mode Commands for CoS 3271 Copyright 2010 Juniper Networks Inc ...
Page 3435: ...CHAPTER 120 Operational Mode Commands for PoE 3339 Copyright 2010 Juniper Networks Inc ...
Page 3529: ...CHAPTER 126 Operational Mode Commands for MPLS 3433 Copyright 2010 Juniper Networks Inc ...