set dhcpsnooping log-invalid
17-8 DHCP Snooping and Dynamic ARP Inspection
Parameters
Defaults
SourceMACaddressverificationisenabledbydefault.
Mode
Switchcommand,read‐write.
Usage
Whenthisverificationisenabled,theDHCPsnoopingapplicationcomparesthesourceMAC
addresscontainedinvalidclientmessageswiththeclient’shardwareaddress.Ifthereisa
mismatch,DHCPsnoopinglogstheeventanddropsthepacket.
Usetheshow dhcpsnoopingcommandtodisplaythestatus(enabledordisabled)of
sourceMAC
addressverificationforeachinterfaceinanenabledVLAN.Theshow dhcpsnoopingstatistics
commandshowstheactualnumberofMACverificationerrorsthatoccurredonuntrustedports.
Example
ThisexampledisablessourceMACaddressverificationandlogging.
C2
(rw)->set dhcpsnooping verify mac-address disable
set dhcpsnooping log-invalid
UsethiscommandtoenableordisableloggingofinvalidDHCPmessagesonports.
Syntax
set dhcpsnooping log-invalid port port-string {enable | disable}
Parameters
Defaults
Disabled.
Mode
Switchcommand,read‐write.
Usage
TheDHCPsnoopingapplicationprocessesincomingDHCPmessages.ForDHCPRELEASEand
DHCPDECLINEmessages,theapplicationcomparesthereceiveinterface andVLANwiththe
enable EnablesverificationofthesourceMACaddressinclientmessages
againsttheclienthardwareaddress.
disable DisablesverificationofthesourceMACaddressinclientmessages
againstthe
clienthardwareaddress.
portport‐string Specifiestheportorports onwhichtoenableordisableloggingof
invalidpackets.
enable|disable Enablesordisablesloggingonthespecifiedports.