![ZyXEL Communications OLT2406 User Manual Download Page 549](http://html1.mh-extra.com/html/zyxel-communications/olt2406/olt2406_user-manual_944800549.webp)
Chapter 77 IP Source Guard
OLT2406 User’s Guide
549
Trusted ports are connected to DHCP servers or other switches. The OLT discards DHCP packets from
trusted ports only if the rate at which DHCP packets arrive is too high. The OLT learns dynamic bindings
from trusted ports.
Note: The OLT will drop all DHCP requests if you enable DHCP snooping and there are no
trusted ports.
Untrusted ports are connected to subscribers. The OLT discards DHCP packets from untrusted ports in the
following situations:
• The packet is a DHCP server packet (For example, OFFER, ACK, or NACK).
• The source MAC address and source IP address in the packet do not match any of the current
bindings.
• The packet is a RELEASE or DECLINE packet, and the source MAC address and source port do not
match any of the current bindings.
• The rate at which DHCP packets arrive is too high.
77.1.1.2 DHCP Snooping Database
The OLT stores the binding table in volatile memory. If the OLT restarts, it loads static bindings from
permanent memory but loses the dynamic bindings, in which case the devices in the network have to
send DHCP requests again. As a result, it is recommended you configure the DHCP snooping database.
The DHCP snooping database maintains the dynamic bindings for DHCP snooping and ARP inspection
in a file on an external TFTP server. If you set up the DHCP snooping database, the OLT can reload the
dynamic bindings from the DHCP snooping database after the OLT restarts.
You can configure the name and location of the file on the external TFTP server. The file has the following
format:
Figure 272
DHCP Snooping Database File Format
The <initial-checksum> helps distinguish between the bindings in the latest update and the bindings
from previous updates. Each binding consists of 72 bytes, a space, and another checksum that is used
to validate the binding when it is read. If the calculated checksum is not equal to the checksum in the
file, that binding and all others after it are ignored.
77.1.1.3 DHCP Relay Option 82 Information
The OLT can add information to DHCP requests that it does not discard. This provides the DHCP server
more information about the source of the requests. The OLT can add the following information:
• Slot ID (One byte), port ID (One byte), and source VLAN ID (Two bytes)
<initial-checksum>
TYPE DHCP-SNOOPING
VERSION 1
BEGIN
<binding-1> <checksum-1>
<binding-2> <checksum-1-2>
...
...
<binding-n> <checksum-1-2-..-n>
END
Summary of Contents for OLT2406
Page 4: ...Document Conventions OLT2406 User s Guide 4 Desktop Laptop Switch IP Phone Smart T V...
Page 32: ...Table of Contents OLT2406 User s Guide 32 Index 758...
Page 33: ...33 PART I Introduction and Hardware Installation...
Page 63: ...63 PART II Web Configurator...
Page 179: ...Chapter 21 Classifier OLT2406 User s Guide 179 Figure 112 Classifier Example...
Page 182: ...Chapter 22 Policy Rule OLT2406 User s Guide 182 Figure 113 Advanced Application Policy Rule...
Page 186: ...Chapter 22 Policy Rule OLT2406 User s Guide 186 Figure 114 Policy Example...
Page 248: ...Chapter 28 Loop Guard OLT2406 User s Guide 248 Figure 151 Advanced Application Loop Guard...
Page 393: ...393 PART III CLI Commands...
Page 581: ...Chapter 78 VoIP OLT2406 User s Guide 581...
Page 725: ...725 PART IV Troubleshooting Specifications Appendices and Index...