Specifications
set dhcpsnooping binding
SecureStack B2 Configuration Guide 18-7
Defaults
Bydefault,portsareuntrusted.
Mode
Switchcommand,read‐write.
Usage
InorderforDHCPsnoopingtooperate,snoopinghastobeenabledgloballyandonspecific
VLANs,andtheportswithintheVLANshavetobeconfiguredastrustedoruntrusted.On
trustedports,DHCPclientmessagesareforwardeddirectlybythehardware.Onuntrustedports,
clientmessagesaregivento
theDHCPsnoopingapplication.
TheDHCPsnoopingapplicationbuildsthebindingsdatabasefromclientmessagesreceivedon
untrustedports.DHCPsnoopingcreatesa“tentativebinding”fromDHCPDISCOVERand
REQUESTmessages.Tent ativebindingstieaclienttotheportonwhichthemessagepacketwas
received.Tentativebindingsarecompletedwhen
DHCPsnoopinglearnstheclient’sIPaddress
fromaDHCPACKmessageonatrustedport.
TheportsontheswitchthroughwhichDHCPserversarereachedmustbeconfiguredastrusted
portssothatpacketsreceivedfromthoseportswillbeforwardedtoclients.DCHPpacketsfroma
DHCP
server(DHCPOFFER,DHCPACK,DHCPNAK)aredroppedifreceivedonanuntrusted
port.
Example
Thisexampleconfiguresportge.1.1asatrustedport.
B2
(rw)->set dhcpsnooping trust port ge.1.1 enable
set dhcpsnooping binding
UsethiscommandtoaddastaticDHCPbindingtotheDHCP snoopingdatabase.
Syntax
set dhcpsnooping binding mac-address vlan vlan-id ipaddr port port-string
Parameters
Defaults
None.
Mode
Switchcommand,read‐write.
enable|disable Enablesordisablesthespecifiedportsastrustedports.
mac‐address SpecifiestheMACaddressofthebindingentry.
vlanvlan‐id SpecifiestheVLANofthebindingentry.
ipaddr SpecifiestheIPaddressofthebindingentry.
portport‐string Specifiestheportofthebindingentry.