Chapter 23 IP Source Guard
MGS-3712/MGS-3012F User’s Guide
186
Trusted ports are connected to DHCP servers or other switches. The Switch discards DHCP
packets from trusted ports only if the rate at which DHCP packets arrive is too high. The
Switch learns dynamic bindings from trusted ports.
"
If DHCP is enabled and there are no trusted ports, DHCP requests will not
succeed.
Untrusted ports are connected to subscribers. The Switch discards DHCP packets from
untrusted ports in the following situations:
• The packet is a DHCP server packet (for example, OFFER, ACK, or NACK).
• The source MAC address and source IP address in the packet do not match any of the
current bindings.
• The packet is a RELEASE or DECLINE packet, and the source MAC address and source
port do not match any of the current bindings.
• The rate at which DHCP packets arrive is too high.
23.1.1.2 DHCP Snooping Database
The Switch stores the binding table in volatile memory. If the Switch restarts, it loads static
bindings from permanent memory but loses the dynamic bindings, in which case the devices in
the network have to send DHCP requests again. As a result, it is recommended you configure
the DHCP snooping database.
The DHCP snooping database maintains the dynamic bindings for DHCP snooping and ARP
inspection in a file on an external TFTP server. If you set up the DHCP snooping database, the
Switch can reload the dynamic bindings from the DHCP snooping database after the Switch
restarts.
You can configure the name and location of the file on the external TFTP server. The file has
the following format:
Figure 102
DHCP Snooping Database File Format
The <initial-checksum> helps distinguish between the bindings in the latest update and the
bindings from previous updates. Each binding consists of 72 bytes, a space, and another
checksum that is used to validate the binding when it is read. If the calculated checksum is not
equal to the checksum in the file, that binding and all others after it are ignored.
<initial-checksum>
TYPE DHCP-SNOOPING
VERSION 1
BEGIN
<binding-1> <checksum-1>
<binding-2> <checksum-1-2>
...
...
<binding-n> <checksum-1-2-..-n>
END
Summary of Contents for MGS-3712
Page 2: ......
Page 7: ...Safety Warnings MGS 3712 MGS 3012F User s Guide 7 ...
Page 8: ...Safety Warnings MGS 3712 MGS 3012F User s Guide 8 ...
Page 20: ...Table of Contents MGS 3712 MGS 3012F User s Guide 20 ...
Page 28: ...List of Tables MGS 3712 MGS 3012F User s Guide 28 ...
Page 30: ...30 ...
Page 38: ...Chapter 2 Hardware Installation and Connection MGS 3712 MGS 3012F User s Guide 38 ...
Page 50: ...50 ...
Page 70: ...Chapter 6 System Status and Port Statistics MGS 3712 MGS 3012F User s Guide 70 ...
Page 82: ...Chapter 7 Basic Setting MGS 3712 MGS 3012F User s Guide 82 ...
Page 84: ...84 ...
Page 132: ...Chapter 15 Link Aggregation MGS 3712 MGS 3012F User s Guide 132 ...
Page 142: ...Chapter 17 Port Security MGS 3712 MGS 3012F User s Guide 142 ...
Page 148: ...Chapter 18 Classifier MGS 3712 MGS 3012F User s Guide 148 Figure 80 Classifier Example ...
Page 153: ...Chapter 19 Policy Rule MGS 3712 MGS 3012F User s Guide 153 Figure 83 Policy Example ...
Page 154: ...Chapter 19 Policy Rule MGS 3712 MGS 3012F User s Guide 154 ...
Page 170: ...Chapter 21 Multicast MGS 3712 MGS 3012F User s Guide 170 ...
Page 184: ...Chapter 22 Authentication Accounting MGS 3712 MGS 3012F User s Guide 184 ...
Page 214: ...Chapter 25 Two Rate Three Color Marker MGS 3712 MGS 3012F User s Guide 214 ...
Page 215: ...215 PART IV IP Application Static Route 217 DHCP 221 ...
Page 216: ...216 ...
Page 220: ...Chapter 26 Static Route MGS 3712 MGS 3012F User s Guide 220 ...
Page 228: ...Chapter 27 DHCP MGS 3712 MGS 3012F User s Guide 228 ...
Page 230: ...230 ...
Page 256: ...Chapter 30 Diagnostic MGS 3712 MGS 3012F User s Guide 256 ...
Page 260: ...Chapter 31 Syslog MGS 3712 MGS 3012F User s Guide 260 ...
Page 274: ...274 ...
Page 278: ...Chapter 36 Troubleshooting MGS 3712 MGS 3012F User s Guide 278 ...
Page 286: ...286 ...
Page 290: ...Appendix A Common Services MGS 3712 MGS 3012F User s Guide 290 ...
Page 294: ...Appendix B Legal Information MGS 3712 MGS 3012F User s Guide 294 ...