632 CHAPTER 59: DHCP S NOOPING CONFIGURATIONn ■ Enable DHCP snooping and specify trusted ports on the switch beforeconfiguring IP filtering.■ You are not recommended to configure IP filtering on the ports of anaggregation group.Displaying andMaintaining DHCPSnoopingAfter the above configuration, execute the display command in any view todisplay and verify the DHCP snooping configuration.Execute the reset command in user view to clear the IP-MAC mappings recordedby the DHCP-Snooping-enabled switch.DHCP SnoopingConfigurationExampleDHCP Snooping TrustedPort ConfigurationExampleNetwork requirementsAs shown in Figure 163, the Ethernet 2/0/1 port of Switch A is connected toSwitch B (acting as a DHCP relay agent). A network segment containing someDHCP clients is connect to the Ethernet 2/0/2 port of Switch A.■ The DHCP snooping function is enabled on Switch A.■ The DHCP-Snooping-enabled device supports option 82 and option 82 isenabled on the switch.■ The Ethernet 2/0/1 port of Switch A is a trusted port.Create a static binding ip source static bindingip-address ip-address[ mac-address mac-address ]OptionalBy default, no static bindingentry is created.Table 505 Configure IP filteringOperation Command DescriptionTable 506 Display and maintain DHCP snooping configurationOperation Command DescriptionDisplay the IP-MAC mappingsrecorded by theDHCP-Snooping-enabled switchdisplay dhcp-snooping You canexecute thedisplaycommand inany view.Display DHCP-Snooping status andtrusted port informationdisplay dhcp-snooping trustDisplay the total number ofDHCP-Snooping binding table entriesdisplay dhcp-snooping countDisplay the DHCP-Snooping bindingtable entries of the specified VLANdisplay dhcp-snoopingvlan { vlan-list | all }Display IP static binding table entries display ip source static binding[ vlan vlan-id | interfaceinterface-type interface-number ]Clear the IP-MAC mappings recordedby the DHCP-Snooping-enabledswitchreset dhcp-snooping [ ip-address ] You canexecute thereset commandin user view.