WEB Configuration Manual
- 31 -
After the DHCP Snooping function is enabled on the VLAN, the DHCP messages received by all
untrusted physical ports on the entire VLAN will be legally inspected. Any responded DHCP
messages received by untrusted physical ports within a VLAN will be lost to prevent users from
counterfeiting messages or prevent a mistaken DHCP server from assigning addresses. For the
DHCP requests from untrusted ports, if the MAC address does not match the hardware address
field in the messages, the requests will be considered as attacking messages counterfeited by
users for the purpose of DHCP DOS (denial of service) and the switch will be abandoned too.
Monitor the ARP dynamics of all physical ports of a VLAN. If the source MAC and IP addresses of
the ARP messages received by the ports do not match the MAC and IP address binding relations
configured for the ports, the messages cannot be processed. The binding relations configured for
the ports may be dynamic along with the DHCP or manually configured. If no MAC and IP address
binding relations are configured for a physical port, the switch will refuse to forward all the ARP
messages.
In a VLAN where IP source addresses are monitored, if the source MAC and IP addresses of the IP
messages received by all the physical ports in the VLAN do not match the MAC and IP address
binding relations configured for the ports, the messages cannot be processed. The binding
relations configured for the ports may be dynamic along with the DHCP or manually configured. If
no MAC and IP address binding relations are configured for a physical port, the switch will refuse to
forward all the IP messages received by all the ports.
6.2.3 DHCP Snooping Interface Configuration
Click
Network Security -> DHCP Snooping -> Interface Config
at navigation bar in order
to enter
DHCP Snooping Port configuration page as following:
If a port is configured as the DHCP-trusted port, the DHCP messaged received by this port will not
be inspected.
The ARP monitoring function will not be enabled for ARP-trusted ports. Ports are untrusted by
default.
The source address inspection function is not enabled for ports trusted by IP source addresses.
6.2.4
DHCP Snooping Bindings
Click
Network Security -> DHCP Snooping -> Bindings
at navigation bar in order
to enter DHCP
Snooping Binding configuration page as following: