Chapter 26 IP Source Guard
XGS4700-48F User’s Guide
262
26.1.1 DHCP Snooping Overview
Use DHCP snooping to filter unauthorized DHCP packets on the network and to
build the binding table dynamically. This can prevent clients from getting IP
addresses from unauthorized DHCP servers.
26.1.1.1 Trusted vs. Untrusted Ports
Every port is either a trusted port or an untrusted port for DHCP snooping. This
setting is independent of the trusted/untrusted setting for ARP inspection. You can
also specify the maximum number for DHCP packets that each port (trusted or
untrusted) can receive each second.
Trusted ports are connected to DHCP servers or other switches. The Switch
discards DHCP packets from trusted ports only if the rate at which DHCP packets
arrive is too high. The Switch learns dynamic bindings from trusted ports.
Note: The Switch will drop all DHCP requests if you enable DHCP snooping and there
are no trusted ports.
Untrusted ports are connected to subscribers. The Switch discards DHCP packets
from untrusted ports in the following situations:
• The packet is a DHCP server packet (for example, OFFER, ACK, or NACK).
• The source MAC address and source IP address in the packet do not match any
of the current bindings.
• The packet is a RELEASE or DECLINE packet, and the source MAC address and
source port do not match any of the current bindings.
• The rate at which DHCP packets arrive is too high.
26.1.1.2 DHCP Snooping Database
The Switch stores the binding table in volatile memory. If the Switch restarts, it
loads static bindings from permanent memory but loses the dynamic bindings, in
which case the devices in the network have to send DHCP requests again. As a
result, it is recommended you configure the DHCP snooping database.
The DHCP snooping database maintains the dynamic bindings for DHCP snooping
and ARP inspection in a file on an external TFTP server. If you set up the DHCP
snooping database, the Switch can reload the dynamic bindings from the DHCP
snooping database after the Switch restarts.
Summary of Contents for XGS4700 Series
Page 2: ......
Page 8: ...Safety Warnings XGS4700 48F User s Guide 8...
Page 24: ...Table of Contents XGS4700 48F User s Guide 24...
Page 25: ...25 PART I User s Guide...
Page 26: ...26...
Page 32: ...Chapter 1 Getting to Know Your Switch XGS4700 48F User s Guide 32...
Page 54: ...Chapter 3 Hardware Overview XGS4700 48F User s Guide 54...
Page 97: ...97 PART II Technical Reference...
Page 98: ...98...
Page 104: ...Chapter 7 System Status and Port Statistics XGS4700 48F User s Guide 104...
Page 118: ...Chapter 8 Basic Setting XGS4700 48F User s Guide 118...
Page 138: ...Chapter 9 VLAN XGS4700 48F User s Guide 138...
Page 142: ...Chapter 10 Static MAC Forward Setup XGS4700 48F User s Guide 142...
Page 174: ...Chapter 14 Bandwidth Control XGS4700 48F User s Guide 174...
Page 188: ...Chapter 17 Link Aggregation XGS4700 48F User s Guide 188...
Page 198: ...Chapter 18 Port Authentication XGS4700 48F User s Guide 198...
Page 216: ...Chapter 21 Policy Rule XGS4700 48F User s Guide 216...
Page 260: ...Chapter 25 AAA XGS4700 48F User s Guide 260...
Page 284: ...Chapter 26 IP Source Guard XGS4700 48F User s Guide 284...
Page 316: ...Chapter 32 Error Disable XGS4700 48F User s Guide 316...
Page 320: ...Chapter 33 Static Route XGS4700 48F User s Guide 320...
Page 328: ...Chapter 35 RIP XGS4700 48F User s Guide 328...
Page 384: ...Chapter 42 ARP Learning XGS4700 48F User s Guide 384...
Page 420: ...Chapter 45 Access Control XGS4700 48F User s Guide 420...
Page 426: ...Chapter 47 Syslog XGS4700 48F User s Guide 426...
Page 434: ...Chapter 48 Cluster Management XGS4700 48F User s Guide 434...
Page 438: ...Chapter 49 MAC Table XGS4700 48F User s Guide 438...
Page 442: ...Chapter 50 IP Table XGS4700 48F User s Guide 442...
Page 446: ...Chapter 52 Routing Table XGS4700 48F User s Guide 446...
Page 454: ...Chapter 54 Troubleshooting XGS4700 48F User s Guide 454...
Page 464: ...Chapter 55 Product Specifications XGS4700 48F User s Guide 464...
Page 473: ...Appendix B Legal Information XGS4700 48F User s Guide 473...
Page 474: ...Appendix B Legal Information XGS4700 48F User s Guide 474...