All MIBs › CISCOSB-BRIDGE-SECURITY › rlIpDhcpSnoopVerifyMacAddress
rlIpDhcpSnoopVerifyMacAddress
Module: CISCOSB-BRIDGE-SECURITY
OID (symbolic): CISCOSB-BRIDGE-SECURITY::rlIpDhcpSnoopVerifyMacAddress
OID (numeric): 1.3.6.1.4.1.9.6.1.101.112.1.6
Node type: OBJECT-TYPE
Type: INTEGER
Access: read-write
Description: Configures on an un-trusted port whether the source MAC address in a DHCP packet matches the client hardware address.
What is rlIpDhcpSnoopVerifyMacAddress?
This read-write INTEGER (enable(1)/disable(2)) configures whether, on untrusted ports, the switch checks that the source MAC address in the Ethernet header of a DHCP packet matches the client hardware address field inside the DHCP payload. An admin cares because this catches spoofed DHCP packets that try to disguise their true origin, strengthening the effectiveness of DHCP snooping. For example, an admin hardening an untrusted access port against MAC spoofing attacks used to poison DHCP snooping bindings would enable this verification.
Examples
Walk all instances (SNMPv2c):
snmpwalk -v2c -c public <target> 1.3.6.1.4.1.9.6.1.101.112.1.6 snmpwalk -v2c -c public <target> CISCOSB-BRIDGE-SECURITY::rlIpDhcpSnoopVerifyMacAddress
Get a specific instance (index 1):
snmpget -v2c -c public <target> 1.3.6.1.4.1.9.6.1.101.112.1.6.1 snmpget -v2c -c public <target> CISCOSB-BRIDGE-SECURITY::rlIpDhcpSnoopVerifyMacAddress.1
Set instance 1 (SNMPv2c):
snmpset -v2c -c private <target> 1.3.6.1.4.1.9.6.1.101.112.1.6.1 i <value>
SNMPv3 example:
snmpget -v3 -l authPriv -u snmpv3-user -a SHA -A "AuthPassword1" -x AES -X "PrivPassword1" <target> rlIpDhcpSnoopVerifyMacAddress.1
Start monitoring Cisco Small Business managed switch with a free 30-day trial of IPNetwork Monitor. Create custom SNMP monitor using the CISCOSB-BRIDGE-SECURITY::rlIpDhcpSnoopVerifyMacAddress OID value, configure state conditions and alerts, and monitor any Cisco Small Business managed switch from a single console.
OID Breakdown
Upper-level ancestors (10 from the standard OID tree / other modules)
| Numeric OID | Name | Module |
|---|---|---|
| 1 | iso | LANART-AGENT |
| 1.3 | org | AirPair-MIB |
| 1.3.6 | dod | AirPair-MIB |
| 1.3.6.1 | internet | AirPair-MIB |
| 1.3.6.1.4 | private | AirPair-MIB |
| 1.3.6.1.4.1 | enterprises | AirPair-MIB |
| 1.3.6.1.4.1.9 | cisco | CAT2600-MIB |
| 1.3.6.1.4.1.9.6 | otherEnterprises | CISCO-SMI |
| 1.3.6.1.4.1.9.6.1 | ciscoSB | CISCO-SMI |
| 1.3.6.1.4.1.9.6.1.101 | switch001 | CISCOSB-MIB |
| Numeric OID | Name | Module |
|---|---|---|
| 1.3.6.1.4.1.9.6.1.101.112 | rlBridgeSecurity | CISCOSB-BRIDGE-SECURITY |
| 1.3.6.1.4.1.9.6.1.101.112.1 | rlIpDhcpSnoop | CISCOSB-BRIDGE-SECURITY |
| 1.3.6.1.4.1.9.6.1.101.112.1.6 | rlIpDhcpSnoopVerifyMacAddress | CISCOSB-BRIDGE-SECURITY |