Access Security Guide K/KA/KB.15.15

10 No - - -
11 Yes - - -
12 Yes - - -
13 No - - -
14 No - - -
15 No - - -
16 No - 2 8
17 No 21 12 24
18 Yes - - -
19 No - - -
20 No - - -
21 No - - -
22 No - - -
23 No - - -
24 Yes - - -
Syntax
(config)# show dhcp-snooping stats
Shows the dhcp-snooping statistics.
Packet type Action Reason Count
----------- ------- ---------------------------- ---------
server forward from trusted port 0
client forward to trusted port 0
server drop received on untrusted port 0
server drop unauthorized server 0
client drop destination on untrusted port 0
client drop untrusted option 82 field 0
client drop bad DHCP release request 0
client drop failed verify MAC check 0
client drop failed on max-binding limit 0
Enabling debug logging
To enable debug logging for DHCP snooping, use this command.
Syntax
[no]debug security dhcp-snooping [agent | event | packet]
agent
Displays DHCP snooping agent messages.
event
Displays DHCP snooping event messages.
packet
Displays DHCP snooping packet messages.
Enabling Dynamic ARP protection
To enable dynamic ARP protection for VLAN traffic on a routing switch, enter the arp-protect
vlan command at the global configuration level.
Syntax
[no]arp-protect vlan [vlan-range]
vlan-range
Specifies a VLAN ID or a range of VLAN IDs from one to 4094; for example,
1–200.
An example of the arp-protect vlancommand is shown here:
HP Switch(config)# arp-protect vlan 1-101
Using Port Security 375