Previous Topic

Next Topic

Book Contents

DHCP Snooping Configuration Commands

This section describes commands you use to configure DHCP Snooping.

ip dhcp snooping

Use this command to enable DHCP Snooping globally.

no ip dhcp snooping

Use this command to disable DHCP Snooping globally.

ip dhcp snooping vlan

Use this command to enable DHCP Snooping on a list of comma-separated VLAN ranges.

no ip dhcp snooping vlan

Use this command to disable DHCP Snooping on VLANs.

ip dhcp snooping verify mac-address

Use this command to enable verification of the source MAC address with the client hardware address in the received DCHP message.

no ip dhcp snooping verify mac-address

Use this command to disable verification of the source MAC address with the client hardware address.

ip dhcp snooping database

Use this command to configure the persistent location of the DHCP Snooping database. This can be local or a remote file on a given IP machine.

ip dhcp snooping database write-delay

Use this command to configure the interval in seconds at which the DHCP Snooping database will be persisted. The interval value ranges from 15 to 86400 seconds.

no ip dhcp snooping database write-delay

Use this command to set the write delay value to the default value.

ip dhcp snooping binding

Use this command to configure static DHCP Snooping binding.

no ip dhcp snooping binding

Use this command to remove the DHCP static entry from the DHCP Snooping database.

ip verify binding

Use this command to configure static IP source guard (IPSG) entries.

no ip verify binding

Use this command to remove the IPSG static entry from the IPSG database.

ip dhcp snooping limit

Use this command to control the rate at which the DHCP Snooping messages come on an interface or range of interfaces. By default, rate limiting is disabled. When enabled, the rate can range from 0 to 30 packets per second. The burst level range is 1 to 15 seconds.

no ip dhcp snooping limit

Use this command to set the rate at which the DHCP Snooping messages come, and the burst level, to the defaults.

ip dhcp snooping log-invalid

Use this command to control the logging DHCP messages filtration by the DHCP Snooping application. This command can be used to configure a single interface or a range of interfaces.

no ip dhcp snooping log-invalid

Use this command to disable the logging DHCP messages filtration by the DHCP Snooping application.

ip dhcp snooping trust

Use this command to configure an interface or range of interfaces as trusted.

no ip dhcp snooping trust

Use this command to configure the port as untrusted.

ip verify source

Use this command to configure the IPSG source ID attribute to filter the data traffic in the hardware. Source ID is the combination of IP address and MAC address. Normal command allows data traffic filtration based on the IP address. With the "port-security" option, the data traffic will be filtered based on the IP and MAC addresses.

This command can be used to configure a single interface or a range of interfaces.

no ip verify source

Use this command to disable the IPSG configuration in the hardware. You cannot disable port-security alone if it is configured.

show ip dhcp snooping

Use this command to display the DHCP Snooping global configurations and per port configurations.

The display parameters for above command are:

show ip dhcp snooping binding

Use this command to display the DHCP Snooping binding entries. To restrict the output, use the following options:

The display parameters for above command are:

show ip dhcp snooping database

Use this command to display the DHCP Snooping configuration related to the database persistency.

The display parameters for above command are:

show ip dhcp snooping interfaces

Use this command to show the DHCP Snooping status of the interfaces.

show ip dhcp snooping statistics

Use this command to list statistics for DHCP Snooping security violations on untrusted ports.

The display parameters for above command are:

clear ip dhcp snooping binding{static/dynamic}

Use this command to clear all DHCP snooping bindings on all interfaces based on static or dynamic type.

clear ip dhcp snooping binding interface-number

Use this command to clear all DHCP snooping bindings on a specific interface or clear based on static or dynamic type for a specific interface.

clear ip dhcp snooping binding vlan-id

Use this command to clear all DHCP snooping bindings on a specific vlan or clear based on static or dynamic type for a specific vlan.

clear ip dhcp snooping statistics

Use this command to clear all DHCP Snooping statistics.

show ip verify source

Use this command to display the IPSG configurations on all ports.

The display parameters for above command are:

show ip verify interface

Use this command to display the IPSG filter type for a specific interface.

The display parameters for above command are:

show ip source binding

Use this command to display the IPSG bindings.

The display parameters for above command are:

See also

Switching Commands

Port Configuration Commands

Spanning Tree Protocol (STP) Commands

VLAN Commands

Private VLAN Commands

Ethernet Ring Protection Commands

Double VLAN Commands

Voice VLAN Commands

Provider Bridge Commands

802.1AS Timesync Commands

Provisioning (IEEE 802.1p) Commands

Protected Ports Commands

GARP Commands

GVRP Commands

GMRP Commands

Port-Based Network Access Control Commands

Switch Port Auto-recovery (SPAR) Commands

802.1X Supplicant Commands

Storm-Control Commands

Link Local Protocol Filtering Commands

MMRP Commands

MSRP Commands

MVRP Commands

Port-Channel/LAG (802.3ad) Commands

Port Mirroring

Static MAC Filtering

DHCP L2 Relay Agent Comamnds

DHCP Client Commands

Dynamic ARP Inspection Commands

IGMP Snooping Configuration Commands

IGMP Snooping Querier Commands

MLD Snooping Commands

MLD Snooping Querier Commands

Port Security Commands

LLDP (802.1AB) Commands

LLDP-MED Commands

Denial of Service Commands

MAC Database Commands

ISDP Commands

Ethernet in the First Mile Operations and Maintenance Commands

Connectivity Fault Management Commands