Chapter 24 IP Source Guard
XS3900-48F User’s Guide
201
24.1.1 IP Source Guard Menu Overview
24.1.2 DHCP Snooping Overview
Use DHCP snooping to filter unauthorized DHCP packets on the network and to build the binding
table dynamically. This can prevent clients from getting IP addresses from unauthorized DHCP
servers.
24.1.2.1 Trusted vs. Untrusted Ports
Every port is either a trusted port or an untrusted port for DHCP snooping. This setting is
independent of the trusted/untrusted setting for ARP inspection. You can also specify the maximum
number for DHCP packets that each port (trusted or untrusted) can receive each second.
Trusted ports are connected to DHCP servers or other switches. The Switch discards DHCP packets
from trusted ports only if the rate at which DHCP packets arrive is too high. The Switch learns
dynamic bindings from trusted ports.
Note: The Switch will drop all DHCP requests if you enable DHCP snooping and there are
no trusted ports.
Untrusted ports are connected to subscribers. The Switch discards DHCP packets from untrusted
ports in the following situations:
• The packet is a DHCP server packet (for example, OFFER, ACK, or NACK).
• The source MAC address and source IP address in the packet do not match any of the current
bindings.
• The packet is a RELEASE or DECLINE packet, and the source MAC address and source port do not
match any of the current bindings.
• The rate at which DHCP packets arrive is too high.
24.1.2.2 DHCP Snooping Database
The Switch stores the binding table in volatile memory. If the Switch restarts, it loads static
bindings from permanent memory but loses the dynamic bindings, in which case the devices in the
network have to send DHCP requests again. As a result, it is recommended you configure the DHCP
snooping database.
Table 82
IP Source Guard Menu Overview
MENU
SUB-MENU 1
SUB-MENU 2
SUB-MENU 3
IP Source Guard
Configure
Port
VLAN
VLAN Status
Log Status
Configure
Port
VLAN
Summary of Contents for XS-3900-48F
Page 15: ...15 PART I User s Guide ...
Page 16: ...16 ...
Page 48: ...Chapter 2 Tutorials XS3900 48F User s Guide 48 ...
Page 62: ...Chapter 4 The Web Configurator XS3900 48F User s Guide 62 ...
Page 63: ...63 PART II Technical Reference ...
Page 64: ...64 ...
Page 227: ...Chapter 26 VLAN Mapping XS3900 48F User s Guide 227 ...
Page 320: ...Appendix A Common Services XS3900 48F User s Guide 320 ...
Page 332: ...Index XS3900 48F User s Guide 332 ...