Access Security Guide K/KA/KB.15.15

Syntax
[no]dhcp-snooping [authorized-server | database | option |
trust | verify | vlan]
authorized server
Enter the IP address of a trusted DHCP server. If no authorized servers are
configured, all DHCP server addresses are considered valid. Maximum: 20
authorized servers.
database
To configure a location for the lease database, enter a URL in the format
tftp://ip-addr/ascii-string. The maximum number of characters for
the URL is 63.
option
Add relay information option (Option 82) to DHCP client packets that are being
forwarded out trusted ports. The default is yes, add relay information.
trust
Configure trusted ports. Only server packets received on trusted ports are
forwarded. Default: untrusted.
verify
Enables DHCP packet validation. The DHCP client hardware address field and
the source MAC address must be the same for packets received on untrusted
ports or the packet is dropped. Default: Yes.
vlan
Enable DHCP snooping on a vlan. DHCP snooping must be enabled already.
Default: No.
To display the DHCP snooping configuration, enter this command:
HP Switch(config)# show dhcp-snooping
An example of the output is shown below.
Figure 269 Show dhcp-snooping
To display statistics about the DHCP snooping process, enter this command:
HP Switch(config)# show dhcp-snooping stats
An example of the output is shown below.
370 Port Security