Specifications

set dhcpsnooping binding
SecureStack B2 Configuration Guide 18-7
Defaults
Bydefault,portsareuntrusted.
Mode
Switchcommand,readwrite.
Usage
InorderforDHCPsnoopingtooperate,snoopinghastobeenabledgloballyandonspecific
VLANs,andtheportswithintheVLANshavetobeconfiguredastrustedoruntrusted.On
trustedports,DHCPclientmessagesareforwardeddirectlybythehardware.Onuntrustedports,
clientmessagesaregivento
theDHCPsnoopingapplication.
TheDHCPsnoopingapplicationbuildsthebindingsdatabasefromclientmessagesreceivedon
untrustedports.DHCPsnoopingcreatesa“tentativebinding”fromDHCPDISCOVERand
REQUESTmessages.Tent ativebindingstieaclienttotheportonwhichthemessagepacketwas
received.Tentativebindingsarecompletedwhen
DHCPsnoopinglearnstheclient’sIPaddress
fromaDHCPACKmessageonatrustedport.
TheportsontheswitchthroughwhichDHCPserversarereachedmustbeconfiguredastrusted
portssothatpacketsreceivedfromthoseportswillbeforwardedtoclients.DCHPpacketsfroma
DHCP
server(DHCPOFFER,DHCPACK,DHCPNAK)aredroppedifreceivedonanuntrusted
port.
Example
Thisexampleconfiguresportge.1.1asatrustedport.
B2
(rw)->set dhcpsnooping trust port ge.1.1 enable
set dhcpsnooping binding
UsethiscommandtoaddastaticDHCPbindingtotheDHCP snoopingdatabase.
Syntax
set dhcpsnooping binding mac-address vlan vlan-id ipaddr port port-string
Parameters
Defaults
None.
Mode
Switchcommand,readwrite.
enable|disable Enablesordisablesthespecifiedportsastrustedports.
macaddress SpecifiestheMACaddressofthebindingentry.
vlanvlanid SpecifiestheVLANofthebindingentry.
ipaddr SpecifiestheIPaddressofthebindingentry.
portportstring Specifiestheportofthebindingentry.