beautypg.com

Show ip dhcp snooping, Show ip dhcp snooping binding, Ip source guard – Brocade 6910 Ethernet Access Switch Configuration Guide (Supporting R2.2.0.0) User Manual

Page 276: Table 55

background image

220

Brocade 6910 Ethernet Access Switch Configuration Guide

53-1002651-02

10

IP Source Guard

show ip dhcp snooping

This command shows the DHCP snooping configuration settings.

Command Mode
Privileged Exec

Example

Console#show ip dhcp snooping

Global DHCP Snooping status: disable

DHCP Snooping Information Option Status: disable

DHCP Snooping Information Policy: replace

DHCP Snooping is configured on the following VLANs:

1

Verify Source Mac-Address: enable

Interface Trusted

---------- ----------

Eth 1/1 No

Eth 1/2 No

Eth 1/3 No

Eth 1/4 No

Eth 1/5 Yes

.

.

.

show ip dhcp snooping binding

This command shows the DHCP snooping binding table entries.

Command Mode
Privileged Exec

Example

Console#show ip dhcp snooping binding

MAC Address IP Address Lease(sec) Type VLAN Interface

----------------- --------------- ---------- -------------------- ---- ---------

11-22-33-44-55-66 192.168.0.99 0 Dynamic-DHCPSNP 1 Eth 1/5

Console#

IP Source Guard

IP Source Guard is a security feature that filters IP traffic on network interfaces based on manually
configured entries in the IP Source Guard table, or dynamic entries in the DHCP Snooping table
when enabled (see

“DHCP Snooping”

on page 211). IP source guard can be used to prevent traffic

attacks caused when a host tries to use the IP address of a neighbor to access the network. This
section describes commands used to configure IP Source Guard.

TABLE 55

IP Source Guard Commands

Command

Function

Mode

ip source-guard binding

Adds a static address to the source-guard binding table

GC

ip source-guard

Configures the switch to filter inbound traffic based on source IP
address, or source IP address and corresponding MAC address

IC