Chapter 33 Configuring Dhcp Snooping And Ip Source Guard; Overview Of Dhcp Snooping - Cisco 4500M Software Manual

Software guide
Table of Contents

Advertisement

Configuring DHCP Snooping and IP Source Guard
This chapter describes how to configure Dynamic Host Configuration Protocol (DHCP) snooping and IP
Source Guard on Catalyst 4500 series switches. It provides guidelines, procedures, and configuration
examples.
This chapter consists of the following major sections:
For complete syntax and usage information for the switch commands used in this chapter, refer to the
Note
Catalyst 4500 Series Switch Cisco IOS Command Reference and related publications at
http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/index.htm.

Overview of DHCP Snooping

DHCP snooping is a DHCP security feature that provides security by filtering untrusted DHCP messages
and by building and maintaining a DHCP snooping binding table. An untrusted message is a message
that is received from outside the network or firewall and that can cause traffic attacks within your
network.
The DHCP snooping binding table contains the MAC address, IP address, lease time, binding type,
VLAN number, and interface information that corresponds to the local untrusted interfaces of a switch;
it does not contain information regarding hosts interconnected with a trusted interface. An untrusted
interface is an interface that is configured to receive messages from outside the network or firewall. A
trusted interface is an interface that is configured to receive only messages from within the network.
DHCP snooping acts like a firewall between untrusted hosts and DHCP servers. It also gives you a way
to differentiate between untrusted interfaces connected to the end-user and trusted interfaces connected
to the DHCP server or another switch.
OL-6696-01
Overview of DHCP Snooping, page 33-1
Configuring DHCP Snooping on the Switch, page 33-3
Displaying DHCP Snooping Information, page 33-9
Overview of IP Source Guard, page 33-10
Configuring IP Source Guard on the Switch, page 33-11
Displaying IP Source Guard Information, page 33-13
Displaying IP Source Binding Information, page 33-14
C H A P T E R
Software Configuration Guide—Release 12.2(25)EW
33
33-1

Advertisement

Table of Contents
loading

This manual is also suitable for:

4500 series

Table of Contents