11-7
Configuring Advanced Threat Protection
DHCP Snooping
Figure 11-4. Example of Setting Trusted Ports
DHCP server packets are forwarded only if received on a trusted port; DHCP
server packets received on an untrusted port are dropped.
Use the
no
form of the command to remove the trusted configuration from a
port.
Configuring Authorized Server Addresses
If authorized server addresses are configured, a packet from a DHCP server
must be received on a trusted port AND have a source address in the autho-
rized server list in order to be considered valid. If no authorized servers are
configured, all servers are considered valid. You can configure a maximum of
20 authorized servers.
To configure a DHCP authorized server address, enter this command in the
global configuration context:
HP Switch(config)# dhcp-snooping authorized-server
<ip-address>
HP Switch(config)# dhcp-snooping trust 1-2
HP Switch(config)# show dhcp-snooping
DHCP Snooping Information
DHCP Snooping : Yes
Enabled Vlans : 4
Verify MAC : Yes
Option 82 untrusted policy : drop
Option 82 Insertion : Yes
Option 82 remote-id : mac
Store lease database : Not configured
Port Trust
----- -----
_ 1 Yes
_ 2 Yes
_ 3 No
Summary of Contents for E3800 Series
Page 2: ......
Page 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Page 30: ...xxviii ...
Page 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Page 186: ...4 72 Web and MAC Authentication Client Status ...
Page 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Page 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 730: ...20 Index ...
Page 731: ......