CLI Reference Guide-R04

Table Of Contents
Chapter 9
| General Security Measures
DHCPv4 Snooping
– 332 –
ip dhcp snooping
limit rate
This command sets the maximum number of DHCP packets that can be trapped by
the switch for DHCP snooping. Use the no form to restore the default setting.
Syntax
ip dhcp snooping limit rate rate
no dhcp snooping limit rate
rate - The maximum number of DHCP packets that may be trapped for
DHCP snooping. (Range: 1-2048 packets/second)
Default Setting
Disabled
Command Mode
Global Configuration
Example
This example sets the DHCP snooping rate limit to 100 packets per second.
Console(config)#ip dhcp snooping limit rate 100
Console(config)#
ip dhcp snooping
verify mac address
This command verifies the client’s hardware address stored in the DHCP packet
against the source MAC address in the Ethernet header. Use the no form to disable
this function.
Syntax
[no] ip dhcp snooping verify mac-address
Default Setting
Enabled
Command Mode
Global Configuration
Command Usage
If MAC address verification is enabled, and the source MAC address in the Ethernet
header of the packet is not same as the clients hardware address in the DHCP
packet, the packet is dropped.