Мини Вики. Чтоб ничего не забыть!

ACL для запрета DHCP


Allien Telesys

ip access-list DHCP
deny-udp disable-port any 256 any 67
deny-udp disable-port any 256 any 68
deny-udp disable-port any 256 any 69
exit
interface ethernet e23                      
service-acl input DHCP

SNR

ip access-list extended DHCP2-in
  deny udp any-source host-destination 255.255.255.255 d-port 67
  deny ip host-source 192.168.0.1 any-destination
  deny ip host-source 192.168.1.1 any-destination
  deny ip host-source 192.168.88.1 any-destination
  deny ip any-source host-destination 192.168.0.1
  deny ip any-source host-destination 192.168.1.1
  deny ip any-source host-destination 192.168.88.1
  permit ip any-source any-destination
  exit
!
Interface Ethernet1/0/1
 switchport mode trunk
 switchport trunk allowed vlan 73
 ip access-group DHCP2-in in
 loopback-detection specified-vlan 1-4094
 loopback-detection control shutdown