11.06.2015 Views

ES4626-SFP Management Guide.pdf

ES4626-SFP Management Guide.pdf

ES4626-SFP Management Guide.pdf

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

entries are deleted, the binding ARP list entries can not be recovered untill the DHCP<br />

SNOOPING recapture the biding inforamtion. Adding binding ARP list entries is used to<br />

prevent these list entried from being attacked by ARP cheating. At the same time, these<br />

static list entries need no reauthenticaiton, which can prenvent the switch from the failing<br />

to reauthenticate ARP when it is being attacked by ARP scanning.<br />

Only after the DHCP SNOOPING binding function is enabled, the binding ARP<br />

function can be set.<br />

Example:Enable the DHCP Snooping binding ARP funciton.<br />

switch(Config)#ip dhcp snooping binding arp<br />

Relative Command:ip dhcp snooping binding enable<br />

13.2.2.10 ip dhcp snooping binding dot1x<br />

Command:ip dhcp snooping binding dot1x<br />

no ip dhcp snooping binding dot1x<br />

Function: Enable the DHCP Snooping binding DOT1X funciton.<br />

Parameters:None<br />

Command Mode:Port mode<br />

Default Settings:By default, the binding DOT1X funciton is disabled on all ports.<br />

Usage <strong>Guide</strong>: When this function is enabled, DHCP SNOOPING will notify the DOT1X<br />

module about the captured bindng information as a DOT1X controlled user. This<br />

command is mutually exclusive to”ip dhcp snooping binding user-contro“command.<br />

Only after the DHCP SNOOPING binding function is enabled, the binding ARP<br />

function can be set.<br />

Example:Enable the binding DOT1X funciton on port ethernet1/1<br />

switch(Config)#interface ethernet 1/1<br />

switch(Config- Ethernet 1/1)# ip dhcp snooping binding dot1x<br />

Relative Command:ip dhcp snooping binding enable<br />

ip dhcp snooping binding user-control<br />

13.2.2.11 ip dhcp snooping binding user-control<br />

Command:ip dhcp snooping binding user-control<br />

no ip dhcp snooping binding user-control<br />

Function: Enable the binding user funtion<br />

Parameters:None<br />

Command Mode:Port mode<br />

Default Settings:By default, the binding user funciton is disabled on all ports.<br />

Usage <strong>Guide</strong>: When this function is enabled, DHCP SNOOPING will treat the captured<br />

binding information as trusted users allowed to access all resources. This command is<br />

374

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!