7 dhcp snooping trust, 8 dhcp snooping verify – CANOGA PERKINS 9175 Command Reference User Manual
Page 633
CanogaOS Command Reference
36-6
36.7 dhcp snooping trust
Use the dhcp snooping trust interface configuration command on the switc to configure a port as
trusted for DHCP snooping purposes. Use the no form of this command to return to the default setting.
Command Syntax
dhcp snooping trust
no dhcp snooping trust
Default
DHCP snooping trust is disabled.
Command Mode
Interface configuration
Usage
Configure as trusted ports those that are connected to a DHCP server or to other switches or routers.
Configure as untrusted ports those that are connected to DHCP clients.
Examples
This example shows how to enable DHCP snooping trust on a port:
Switch(config-if)# dhcp snooping trust
Related Commands
show dhcp snooping config
show dhcp snooping binding
36.8 dhcp snooping verify
Use the dhcp snooping verify global configuration command on the switch to configure the switch to
verify on an untrusted port that the source MAC address in a DHCP packet matches the client hardware
address. Use the no form of this command to configure the switch to not verify the MAC addresses.
Command Syntax
dhcp snooping verify mac-address
no dhcp snooping verify mac-address
Default
The switch verifies the source MAC address in a DHCP packet that is received on untrusted ports
matches the client hardware address in the packet.
Command Mode
Global configuration