
Client Security
3-91
Web
– Click DHCP Snooping, VLAN Configuration. Enable DHCP Snooping on the
required VLAN and click Apply.
Figure 3-47 DHCP Snooping VLAN Configuration
CLI
– This example enables DHCP Snooping for VLAN 1.
DHCP Snooping Information Option Configuration
DHCP provides a relay option for sending information about local DHCP clients to
DHCP servers. Also known as DHCP Option 82, it allows compatible DHCP servers
to use this information when assigning IP addresses, or to set other services or
policies for clients. It is also an effective tool in preventing malicious network attacks
from attached clients on DHCP services, such as IP Spoofing, Client Identifier
Spoofing, MAC Address Spoofing, and Address Exhaustion.
Command Usage
• DHCP Snooping (see page 3-90) must be enabled for Option 82 to function.
• When Option 82 is enabled, the requesting client (or an intermediate relay agent
that has used the information fields to describe itself) can be identified in the DHCP
request packets forwarded by the switch and in reply packets sent back from the
DHCP server. Depending on the selected option frame format, this information
may specify the circuit which received the request (including VLAN and port), or
the MAC address of the requesting device (that is, remote device ID).
• If Option 82 is enabled on the switch, client information may be included in any
relayed request packet.
• DHCP request packets are flooded onto all attached VLANs other than the inbound
VLAN under the following situations:
- DHCP snooping is disabled.
- The request packet contains a valid relay agent address field.
• DHCP reply packets received by the relay agent (that is, this switch) are handled
in the following way:
1. When the relay agent receives a DHCP reply packet with Option 82 information,
it first ensures that the packet is destined for it, and then removes the Option 82
field from the packet.
Console(config)#ip dhcp snooping vlan 1
Console(config)#
Содержание ES4524M-PoE
Страница 1: ...Powered by Accton Management Guide ES4524M PoE 24 Port Layer 2 4 Gigabit Ethernet Switch with PoE...
Страница 2: ......
Страница 4: ...ES4524M PoE F1 0 0 5 E012008 ST R01 149100037400A...
Страница 22: ...xviii Tables...
Страница 26: ...xxii Figures...
Страница 34: ...Introduction 1 8 1...
Страница 270: ...Configuring the Switch 3 226...
Страница 404: ...Command Line Interface 4 134 4...
Страница 546: ...Software Specifications A 4 A...
Страница 559: ......
Страница 560: ...ES4524M PoE E012008 ST R01 149100037400A...