CLI Reference Guide-R04

Table Of Contents
Chapter 9
| General Security Measures
DHCPv4 Snooping
– 336 –
ip dhcp snooping
max-number
This command configures the maximum number of DHCP clients which can be
supported per interface. Use the no form to restore the default setting.
Syntax
ip dhcp snooping max-number max-number
no dhcp snooping max-number
max-number - Maximum number of DHCP clients. (Range: 1-32)
Default Setting
16
Command Mode
Interface Configuration (Ethernet, Port Channel)
Example
This example sets the maximum number of DHCP clients supported on port 1 to 2.
Console(config)#interface ethernet 1/1
Console(config-if)#ip dhcp snooping max-number 2
Console(config-if)#
ip dhcp snooping trust This command configures the specified interface as trusted. Use the no form to
restore the default setting.
Syntax
[no] ip dhcp snooping trust
Default Setting
All interfaces are untrusted
Command Mode
Interface Configuration (Ethernet, Port Channel)
Command Usage
A trusted interface is an interface that is configured to receive only messages
from within the network. An untrusted interface is an interface that is
configured to receive messages from outside the network or firewall.
Set all ports connected to DHCP servers within the local network or firewall to
trusted, and all other ports outside the local network or fire wall to untrusted.
When DHCP snooping is enabled globally using the ip dhcp snooping
command, and enabled on a VLAN with ip dhcp snooping vlan command,
DHCP packet filtering will be performed on any untrusted ports within the