Chapter 13: Security Measures
DHCP Snooping
– 364 –
DHCP S
NOOPING
G
LOBAL
C
ONFIGURATION
Use the IP Service > DHCP > Snooping (Configure Global) page to enable
DHCP Snooping globally on the switch, or to configure MAC Address
Verification.
CLI R
EFERENCES
•
P
ARAMETERS
These parameters are displayed:
•
DHCP Snooping Status –
Enables DHCP snooping globally.
(Default: Disabled)
•
DHCP Snooping MAC-Address Verification
– Enables or disables
MAC address verification. If the source MAC address in the Ethernet
header of the packet is not same as the client's hardware address in the
DHCP packet, the packet is dropped. (Default: Enabled)
•
DHCP Snooping Information Option Status
– Enables or disables
DHCP Option 82 information relay. (Default: Disabled)
•
DHCP Snooping Information Option Sub-option Format – Enables or
disables use of sub-type and sub-length fields in circuit-ID (CID) and
remote-ID (RID) in Option 82 information.
•
DHCP Snooping Information Option Remote ID – Specifies the MAC
address, IP address, or arbitrary identifier of the requesting device
(i.e., the switch in this context).
•
MAC Address
– Inserts a MAC address in the remote ID sub-option
for the DHCP snooping agent (i.e., the MAC address of the switch’s
CPU). This attribute can be encoded in Hexadecimal or ASCII.
•
IP Address
– Inserts an IP address in the remote ID sub-option for
the DHCP snooping agent (i.e., the IP address of the management
interface). This attribute can be encoded in Hexadecimal or ASCII.
•
string
- An arbitrary string inserted into the remote identifier field.
(Range: 1-32 characters)
•
DHCP Snooping Information Option Policy
– Specifies how to
handle DHCP client request packets which already contain Option 82
information.
•
Drop
– Drops the client’s request packet instead of relaying it.
•
Keep
– Retains the Option 82 information in the client request, and
forwards the packets to trusted ports.
•
Replace
– Replaces the Option 82 information circuit-id and
remote-id fields in the client’s request with information about the
relay agent itself, inserts the relay agent’s address (when DHCP
snooping is enabled), and forwards the packets to trusted ports.
(This is the default policy.)
Summary of Contents for SSE-G2252
Page 42: ...44 General IP Routing on page 627...
Page 603: ...Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 609...
Page 883: ...Chapter 24 General Security Measures Port based Traffic Segmentation 894...
Page 989: ...Chapter 30 Congestion Control Commands Automatic Traffic Control Commands 1000 Console...
Page 1007: ...Chapter 33 Address Table Commands 1019...
Page 1137: ...Chapter 38 Quality of Service Commands 1150...