Displaying A Binding Table; Displaying The Dhcp Snooping Configuration; Overview Of Ip Source Guard - Cisco 4500M Software Manual

Software guide
Table of Contents

Advertisement

Overview of IP Source Guard

Displaying a Binding Table

The DHCP snooping binding table for each switch contains binding entries that correspond to untrusted
ports. The table does not contain information about hosts interconnected with a trusted port because each
interconnected switch will have its own DHCP snooping binding table.
This example shows how to display the DHCP snooping binding information for a switch:
Switch# sh ip dhcp snooping binding
MacAddress
------------------
00:02:B3:3F:3B:99
Switch#
Table 33-2
Table 33-2 show ip dhcp snooping binding Command Output
Field
MAC Address
IP Address
Lease (seconds)
Type
VLAN
Interface

Displaying the DHCP Snooping Configuration

This example shows how to display the DHCP snooping configuration for a switch.
Switch# show ip dhcp snooping
Switch DHCP snooping is enabled.
DHCP Snooping is configured on the following VLANs:
Insertion of option 82 information is enabled.
Interface
---------
FastEthernet2/1
FastEthernet3/1
GigabitEthernet1/1
Switch#
Overview of IP Source Guard
Similar to DHCP snooping, this feature is enabled on a DHCP snooping untrusted Layer 2 port. Initially,
all IP traffic on the port is blocked except for DHCP packets that are captured by the DHCP snooping
process. When a client receives a valid IP address from the DHCP server, or when a static IP source
binding is configured by the user, a per-port and VLAN Access Control List (PVACL) is installed on the
port. This process restricts the client IP traffic to those source IP addresses configured in the binding;
any IP traffic with a source IP address other than that in the IP source binding will be filtered out. This
filtering limits a host's ability to attack the network by claiming a neighbor host's IP address.
Software Configuration Guide—Release 12.2(25)EW
33-10
IpAddress
---------------
55.5.5.2
describes the fields in the show ip dhcp snooping binding command output.
Description
Client hardware MAC address
Client IP address assigned from the DHCP server
IP address lease time
Binding type; dynamic binding learned by dhcp-snooping or
statically-configured binding.
VLAN number of the client interface
Interface that connects to the DHCP client host
10 30-40 100 200-220
Trusted
-------
yes
yes
no
Chapter 33
Configuring DHCP Snooping and IP Source Guard
Lease(sec)
Type
----------
-------------
6943
dhcp-snooping
Rate limit (pps)
----------------
10
none
20
VLAN
Interface
----
--------------------
10
FastEthernet6/10
OL-6696-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

4500 series

Table of Contents