11-8
Configuring Advanced Threat Protection
DHCP Snooping
Figure 11-5. Example of Authorized Servers for DHCP Snooping
Using DHCP Snooping with Option 82
DHCP adds Option 82 (relay information option) to DHCP request packets
received on untrusted ports by default. (See “Configuring DHCP Relay” in the
Management and Configuration Guide
for more information on Option 82.)
When DHCP is enabled globally and also enabled on a VLAN, and the switch
is acting as a DHCP relay, the settings for the DHCP relay Option 82 command
are ignored when snooping is controlling Option 82 insertion. Option 82
inserted in this manner allows the association of the client’s lease with the
correct port, even when another device is acting as a DHCP relay or when the
server is on the same subnet as the client.
N o t e
DHCP snooping only overrides the Option 82 settings on a VLAN that has
snooping enabled, not on VLANS without snooping enabled.
HP Switch(config)# show dhcp-snooping
DHCP Snooping Information
DHCP Snooping : Yes
Enabled Vlans : 4
Verify MAC : No
Option 82 untrusted policy : drop
Option 82 Insertion : Yes
Option 82 remote-id : subnet-ip
Authorized Servers
---------------------
111.222.3.4
10 0 0 11
Summary of Contents for E3800 Series
Page 2: ......
Page 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Page 30: ...xxviii ...
Page 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Page 186: ...4 72 Web and MAC Authentication Client Status ...
Page 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Page 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 730: ...20 Index ...
Page 731: ......