5-1
5
DHCP Snooping Configuration
When configuring DHCP snooping, go to these sections for information you are interested in:
z
DHCP Snooping Overview
z
Configuring DHCP Snooping Basic Functions
z
Configuring DHCP Snooping to Support Option 82
z
Displaying and Maintaining DHCP Snooping
z
DHCP Snooping Configuration Examples
z
The DHCP snooping enabled device does not work if it is between the DHCP relay agent and
DHCP server, and it can work when it is between the DHCP client and relay agent or between the
DHCP client and server.
z
The S7900E Series Ethernet Switches are distributed devices supporting Intelligent Resilient
Framework (IRF). Two S7900E series can be connected together to form a distributed IRF device.
If an S7900E series is not in any IRF, it operates as a distributed device; if the S7900E series is in
an IRF, it operates as a distributed IRF device. For introduction of IRF, refer to IRF Configuration in
the
System Volume
.
DHCP Snooping Overview
Functions of DHCP Snooping
As a DHCP security feature, DHCP snooping can implement the following:
1) Ensuring DHCP clients to obtain IP addresses from authorized DHCP servers
2) Recording IP-to-MAC mappings of DHCP clients
Ensuring DHCP clients to obtain IP addresses from authorized DHCP servers
If there is an unauthorized DHCP server on a network, DHCP clients may obtain invalid IP addresses
and network configuration parameters, and cannot normally communicate with other network devices.
With DHCP snooping, the ports of a device can be configured as trusted or untrusted, ensuring the
clients to obtain IP addresses from authorized DHCP servers.
z
Trusted: A trusted port forwards DHCP messages normally.
z
Untrusted: An untrusted port discards the DHCP-ACK or DHCP-OFFER messages from any
DHCP server.
You should configure ports that connect to authorized DHCP servers or other DHCP snooping devices
as trusted, and other ports as untrusted. With such configurations, DHCP clients obtain IP addresses
Содержание S7906E - Switch
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45...
Страница 598: ...ii...
Страница 1757: ...4 9...
Страница 1770: ...6 4...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20...