
Chapter 4: Web configuration
NS3562-8P-2S User Manual
159
When the DHCP snooping is globally disabled, DHCP snooping can still be configured
for specific VLANs, but the changes will not take effect until DHCP snooping is globally
enabled.
When DHCP snooping is globally enabled, and DHCP snooping is then disabled on a
VLAN, all dynamic bindings learned for this VLAN are removed from the binding table.
The page includes the following fields:
Object
Description
VLAN List
Indicates the ID of this particular VLAN.
DHCP Snooping
Indicates the DHCP snooping mode operation. Possible modes are:
Enabled
: Enable DHCP snooping mode operation.
When enabling the DHCP snooping mode operation, the request DHCP
messages are forwarded to trusted ports and only permit reply packets from
trusted ports.
Disabled
: Disable DHCP snooping mode operation.
Buttons
• Click
Apply
to apply changes.
Port setting
A trusted interface is an interface that is configured to receive only messages from
within the network. An untrusted interface is an interface that is configured to receive
messages from outside the network or firewall.
When DHCP snooping enabled both globally and on a VLAN, DHCP packet filtering will
be performed on any untrusted ports within the VLAN.
When an untrusted port is changed to a trusted port, all the dynamic DHCP snooping
bindings associated with this port are removed.
Set all ports connected to DHCP servers within the local network or firewall to
Trusted
.
Set all other ports outside the local network or firewall to
Untrusted
.