11.06.2015 Views

ES4626-SFP Management Guide.pdf

ES4626-SFP Management Guide.pdf

ES4626-SFP Management Guide.pdf

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

mutually exclusive to“ ip dhcp snooping binding dot1x“ command.<br />

Only after the DHCP SNOOPING binding function is enabled, the binding ARP<br />

function can be set.<br />

Example:Enable the binding USER funciton on port ethernet1/1<br />

switch(Config)#interface ethernet 1/1<br />

switch(Config- Ethernet 1/1)# ip dhcp snooping binding user-control<br />

Relative Command:ip dhcp snooping binding enable<br />

ip dhcp snooping binding dot1x<br />

13.2.2.12 ip dhcp snooping trust<br />

Command:ip dhcp snooping trust<br />

no ip dhcp snooping trust<br />

Function: Set or delete the DHCP Snooping trust attributes of a port.<br />

Parameters:None<br />

Command Mode:Port mode<br />

Default Settings:By default, all ports are non-trusted ports<br />

Usage <strong>Guide</strong>:<br />

Only when DHCP Snooping is globally enabled, can this command be set.<br />

When a port turns into a trusted port from a non-trusted port, the original defense action<br />

of the port will be automatically deleted; all the security history records will be cleared<br />

(except the information in system log).<br />

Example:Set port ethernet1/1 as a DHCP Snooping trusted port<br />

switch(Config)#interface ethernet 1/1<br />

switch(Config- Ethernet 1/1)#ip dhcp snooping trust<br />

13.2.2.13 ip dhcp snooping action<br />

Command:ip dhcp snooping action {shutdown|blackhole} [recovery ]<br />

no ip dhcp snooping action<br />

Function: Set or delete the automatic defense action of a port.<br />

Parameters:<br />

shutdown: When the port detects a fake DHCP Server, it will be shutdown<br />

blackhole:When the port detects a fake DHCP Server, the vid and source MAC of the<br />

fake packet will be used to block the traffic from this MAC.<br />

Recovery : Users can set to recover after the automatic defense action being<br />

executed.(no shut ports or delete correponding blackhole)<br />

Second:Users can set how long after the execution of defense action to recover. The unit<br />

is second, and valid range is 10-3600.<br />

Command Mode:Port mode<br />

375

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!