CLI Reference Guide-R07

Table Of Contents
Chapter 9
| General Security Measures
DHCPv4 Snooping
– 303 –
VLAN according to the default status, or as specifically configured for an
interface with the no ip dhcp snooping trust command.
When an untrusted port is changed to a trusted port, all the dynamic DHCP
snooping bindings associated with this port are removed.
Additional considerations when the switch itself is a DHCP client – The port(s)
through which it submits a client request to the DHCP server must be
configured as trusted.
Example
This example sets port 5 to untrusted.
Console(config)#interface ethernet 1/5
Console(config-if)#no ip dhcp snooping trust
Console(config-if)#
Related Commands
ip dhcp snooping (291)
ip dhcp snooping vlan (299)
clear ip dhcp
snooping binding
This command clears DHCP snooping binding table entries from RAM. Use this
command without any optional keywords to clear all entries from the binding
table.
Syntax
clear ip dhcp snooping binding mac-address ip-address
mac-address - Specifies a MAC address entry. (Format: xx-xx-xx-xx-xx-xx)
ip-address - Specifies the IP address bound to this entry.
Command Mode
Privileged Exec
Example
Console#clear ip dhcp snooping binding 11-22-33-44-55-66 vlan 1
Console#
clear ip dhcp
snooping database
flash
This command removes all dynamically learned snooping entries from flash
memory.
Command Mode
Privileged Exec