
C
HAPTER
7
| Security Measures
DHCP Snooping
– 240 –
Figure 103: Configuring DHCP Snooping Information Option
C
ONFIGURING
P
ORTS
FOR
DHCP S
NOOPING
Use the DHCP Snooping > Port Configuration page to configure switch
ports as trusted or untrusted.
CLI R
EFERENCES
"ip dhcp snooping trust" on page 631
"ip dhcp snooping information option circuit-id string" on page 631
C
OMMAND
U
SAGE
A trusted interface is an interface that is configured to receive only
messages from within the network. An untrusted interface is an
interface that is configured to receive messages from outside the
network or fire wall.
When DHCP snooping is enabled both globally and on a VLAN, DHCP
packet filtering will be performed on any untrusted ports within the
VLAN.
When an untrusted port is changed to a trusted port, all the dynamic
DHCP snooping bindings associated with this port are removed.
Set all ports connected to DHCP servers within the local network or fire
wall to trusted state. Set all other ports outside the local network or fire
wall to untrusted state.
P
ARAMETERS
These parameters are displayed:
Trust Status
– Enables or disables a port as trusted.
(Default: Disabled)
Circuit ID
– Sets an arbitrary string used in the circuit-id sub-option
field in DHCP Option 82 information. (Range: 1-32 characters)
By default, the switch encodes information for the VLAN, unit number
(i.e., always 1) and port in binary, indicating which port received the
DHCP request packet.
Summary of Contents for DG-FS4528P
Page 2: ......
Page 4: ......
Page 148: ...CHAPTER 5 Simple Network Management Protocol Configuring SNMPv3 Groups 148 ...
Page 389: ...CHAPTER 17 VoIP Traffic Configuration Configuring Telephony OUI 389 ...
Page 515: ...CHAPTER 22 System Management Commands UPnP 515 TTL 20 Console ...
Page 972: ......
Page 973: ...DG FS4528P ...