Chapter 24: General Security Measures
DHCPv6 Snooping
– 857 –
ipv6 dhcp snooping
option remote-id
This command enables the insertion of remote-id option 37 information
into DHCPv6 client messages. Remote-id option information such as the
port attached to the client, DUID, and VLAN ID is used by the DHCPv6
server to assign preassigned configuration data specific to the DHCPv6
client. Use the
no
form of the command to disable this function.
S
YNTAX
[
no
]
ipv6 dhcp snooping option remote-id
D
EFAULT
S
ETTING
Disabled
C
OMMAND
M
ODE
Global Configuration
C
OMMAND
U
SAGE
•
DHCPv6 provides a relay mechanism for sending information about the
switch and its DHCPv6 clients to the DHCPv6 server. Known as DHCPv6
Option 37, it allows compatible DHCPv6 servers to use the information
when assigning IP addresses, or to set other services or policies for
clients.
•
When DHCPv6 Snooping Information Option 37 is enabled, the
requesting client (or an intermediate relay agent that has used the
information fields to describe itself) can be identified in the DHCPv6
request packets forwarded by the switch and in reply packets sent back
from the DHCPv6 server.
•
When the DHCPv6 Snooping Option 37 is enabled, clients can be
identified by the switch port to which they are connected rather than
just their MAC address. DHCPv6 client-server exchange messages are
then forwarded directly between the server and client without having to
flood them to the entire VLAN.
•
DHCPv6 snooping must be enabled for the DHCPv6 Option 37
information to be inserted into packets. When enabled, the switch will
either drop, keep or remove option 37 information in incoming DCHPv6
packets. Packets are processed as follows:
•
If an incoming packet is a DHCPv6 request packet with option 37
information, it will modify the option 37 information according to
settings specified with
ipv6 dhcp snooping option remote-id policy
command.
•
If an incoming packet is a DHCPv6 request packet without option 37
information, enabling the DHCPv6 snooping information option will
add option 37 information to the packet.
•
If an incoming packet is a DHCPv6 reply packet with option 37
information, enabling the DHCPv6 snooping information option will
remove option 37 information from the packet.
Summary of Contents for SSE-G2252
Page 42: ...44 General IP Routing on page 627...
Page 603: ...Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 609...
Page 883: ...Chapter 24 General Security Measures Port based Traffic Segmentation 894...
Page 989: ...Chapter 30 Congestion Control Commands Automatic Traffic Control Commands 1000 Console...
Page 1007: ...Chapter 33 Address Table Commands 1019...
Page 1137: ...Chapter 38 Quality of Service Commands 1150...