![Dell PowerConnect M6220 User Configuration Manual Download Page 787](http://html.mh-extra.com/html/dell/powerconnect-m6220/powerconnect-m6220_user-configuration-manual_84547787.webp)
Snooping and Inspecting Traffic
787
Why Is Traffic Snooping and Inspection Necessary?
DHCP Snooping, IPSG, and DAI are security features that can help protect
the switch and the network against various types of accidental or malicious
attacks. It might be a good idea to enable these features on ports that provide
network access to hosts that are in physically unsecured locations or if
network users connect nonstandard hosts to the network.
For example, if an employee unknowingly connects a workstation to the
network that has a DHCP server, and the DHCP server is enabled, hosts that
attempt to acquire network information from the legitimate network DHCP
server might obtain incorrect information from the rogue DHCP server.
However, if the workstation with the rogue DHCP server is connected to a
port that is configured as untrusted and is a member of a DHCP Snooping-
enabled VLAN, the port discards the DHCP server messages.
Default Traffic Snooping and Inspection Values
DHCP snooping is disabled globally and on all VLANs by default. Ports are
untrusted by default.
Table 27-1. Traffic Snooping Defaults
Parameter
Default Value
DHCP snooping mode
Disabled
DHCP snooping VLAN mode
Disabled on all VLANs
Interface trust state
Disabled (untrusted)
DHCP logging invalid packets
Disabled
DHCP snooping rate limit
15 packets per second
DHCP snooping burst interval
1 second
DHCP snooping binding database
storage
Local
DHCP snooping binding database
write delay
300 seconds
Static DHCP bindings
None configured
IPSG mode
Disabled on all interfaces
IPSG port security
Disabled on all interfaces
Summary of Contents for PowerConnect M6220
Page 52: ...52 Introduction ...
Page 86: ...86 Switch Features ...
Page 100: ...100 Hardware Overview ...
Page 116: ...116 Using the Command Line Interface ...
Page 121: ...Default Settings 121 ...
Page 122: ...122 Default Settings ...
Page 142: ...142 Setting Basic Network Information ...
Page 206: ...206 Configuring Authentication Authorization and Accounting ...
Page 292: ...292 Managing General System Settings Figure 11 31 Verify MOTD ...
Page 296: ...296 Managing General System Settings ...
Page 332: ...332 Configuring SNMP ...
Page 408: ...408 Monitoring Switch Traffic ...
Page 560: ...560 Configuring Access Control Lists ...
Page 591: ...Configuring VLANs 591 Figure 21 17 GVRP Port Parameters Table ...
Page 597: ...Configuring VLANs 597 Figure 21 24 Double VLAN Port Parameter Table ...
Page 693: ...Configuring Port Based Traffic Control 693 Figure 24 3 Storm Control 5 Click Apply ...
Page 780: ...780 Configuring Connectivity Fault Management ...
Page 804: ...804 Snooping and Inspecting Traffic Figure 27 17 DAI Interface Configuration Summary ...
Page 818: ...818 Snooping and Inspecting Traffic ...
Page 836: ...836 Configuring Link Aggregation ...
Page 860: ...860 Configuring Data Center Bridging Features ...
Page 906: ...906 Configuring DHCP Server Settings ...
Page 940: ...940 Configuring L2 and L3 Relay Features Figure 34 3 DHCP Relay Interface Summary ...
Page 1080: ...1080 Configuring VRRP ...
Page 1104: ...1104 Configuring IPv6 Routing ...
Page 1131: ...Configuring Differentiated Services 1131 Figure 40 5 DiffServ Class Criteria ...
Page 1158: ...1158 Configuring Class of Service Figure 41 1 Mapping Table Configuration CoS 802 1P ...
Page 1174: ...1174 Configuring Auto VoIP Figure 42 2 Auto VoIP Interface Configuration ...
Page 1240: ...1240 Managing IPv4 and IPv6 Multicast Figure 43 51 DVMRP Next Hop Summary ...
Page 1266: ...1266 Managing IPv4 and IPv6 Multicast ...
Page 1274: ...1274 System Process Definitions ...
Page 1294: ...1294 Index ...