HP 6125G HP 6125G & 6125G/XG Blade Switches Layer 3 - IP Services Comm - Page 59

dhcp-snooping check request-message, dhcp-snooping information circuit-id format-type

Page 59 highlights

With this function enabled, the DHCP snooping device compares the chaddr field of a received DHCP request with the source MAC address field in the frame. If they are the same, the DHCP snooping device decides this request valid and forwards it to the DHCP server. If not, the DHCP request is discarded. Examples # Enable MAC address check of DHCP snooping. system-view [Sysname] interface GigabitEthernet 1/0/1 [Sysname-GigabitEthernet1/0/1] dhcp-snooping check mac-address dhcp-snooping check request-message Syntax dhcp-snooping check request-message View undo dhcp-snooping check request-message Layer 2 Ethernet port view, Layer 2 aggregate interface view Default level 2: System level Parameters None Description Use dhcp-snooping check request-message to enable DHCP-REQUEST message check of DHCP snooping. Use undo dhcp-snooping check request-message to disable DHCP-REQUEST message check of the DHCP snooping. By default, this function is disabled. With this function enabled, upon receiving a DHCP-REQUEST message, a DHCP snooping device searches local DHCP snooping entries for the corresponding entry of the message. If an entry is found, the DHCP snooping device compares the entry with the message information. If they are consistent, the DHCP-REQUEST message is considered as valid lease renewal request and forwarded to the DHCP server. If they are not consistent, the messages is considered as forged lease renewal request and discarded. If no corresponding entry is found locally, the message is considered valid and forwarded to the DHCP server. Examples # Enable DHCP-REQUEST message check of DHCP snooping. system-view [Sysname] interface GigabitEthernet 1/0/1 [Sysname-GigabitEthernet1/0/1] dhcp-snooping check request-message dhcp-snooping information circuit-id format-type Syntax dhcp-snooping information circuit-id format-type { ascii | hex } 52

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181

52
With this function enabled, the DHCP snooping device compares the chaddr field of a received DHCP
request with the source MAC address field in the frame. If they are the same, the DHCP snooping device
decides this request valid and forwards it to the DHCP server. If not, the DHCP request is discarded.
Examples
# Enable MAC address check of DHCP snooping.
<Sysname> system-view
[Sysname] interface GigabitEthernet 1/0/1
[Sysname-GigabitEthernet1/0/1] dhcp-snooping check mac-address
dhcp-snooping check request-message
Syntax
dhcp-snooping check request-message
undo dhcp-snooping check request-message
View
Layer 2 Ethernet port view, Layer 2 aggregate interface view
Default level
2: System level
Parameters
None
Description
Use
dhcp-snooping check request-message
to enable DHCP-REQUEST message check of DHCP
snooping.
Use
undo dhcp-snooping check request-message
to disable DHCP-REQUEST message check of the
DHCP snooping.
By default, this function is disabled.
With this function enabled, upon receiving a DHCP-REQUEST message, a DHCP snooping device
searches local DHCP snooping entries for the corresponding entry of the message. If an entry is found,
the DHCP snooping device compares the entry with the message information. If they are consistent, the
DHCP-REQUEST message is considered as valid lease renewal request and forwarded to the DHCP
server. If they are not consistent, the messages is considered as forged lease renewal request and
discarded. If no corresponding entry is found locally, the message is considered valid and forwarded to
the DHCP server.
Examples
# Enable DHCP-REQUEST message check of DHCP snooping.
<Sysname> system-view
[Sysname] interface GigabitEthernet 1/0/1
[Sysname-GigabitEthernet1/0/1] dhcp-snooping check request-message
dhcp-snooping information circuit-id format-type
Syntax
dhcp-snooping information circuit-id format-type
{
ascii
|
hex
}