22.05.2017 Views

nx.os.and.cisco.nexus.switching.2nd.edition.1587143046

Nexus Switching 2nd Edition

Nexus Switching 2nd Edition

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Egypt#<br />

Example 5-67 shows how to verify the DHCP Snooping configuration.<br />

Example 5-67. Verifying the DHCP Snooping Configuration<br />

Click here to view code image<br />

Egypt# show ip dhcp snooping<br />

DHCP snooping service is enabled<br />

Switch DHCP snooping is enabled<br />

DHCP snooping is configured on the following VLANs:<br />

5,10,100,500<br />

DHCP snooping is operational on the following VLANs:<br />

5,10,100,500<br />

Insertion of Option 82 is disabled<br />

Verification of MAC address is enabled<br />

DHCP snooping trust is configured on the following<br />

interfaces:<br />

Interface<br />

Trusted<br />

------------ -------<br />

Ethernet1/1<br />

Yes<br />

Egypt#<br />

Egypt# show ip dhcp snooping binding<br />

MacAddress IpAddress LeaseSec Type VLA<br />

0050.561f.73d3 10.10.10.211 1600 dynamic 100<br />

----------------- --------------- -------- ---------<br />

- ---- -------------<br />

Egypt#<br />

The DHCP binding table shows the client MAC address; client IP address assigned from the<br />

DHCP server; IP address lease time; binding type, statically configured from the CLI or<br />

dynamically learned; VLAN number of the client interface; <strong>and</strong> the interface that connects to<br />

the DHCP client h<strong>os</strong>t.<br />

Configuring Dynamic ARP Inspection<br />

Address Resolution Protocol (ARP) provides IP communication within a Layer 2 broadcast<br />

domain by mapping an IP address to a MAC address. There are known security issues with<br />

ARP, such as ARP spoofing attacks. ARP spoofing attacks affect h<strong>os</strong>ts, switches, <strong>and</strong><br />

routers connected to your Layer 2 network by sending false information to the ARP caches<br />

of the devices connected to the subnet.<br />

Dynamic ARP Inspection (DAI) ensures that only valid ARP requests <strong>and</strong> responses are

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!