![Huawei Quidway S5600 Скачать руководство пользователя страница 680](http://html.mh-extra.com/html/huawei/quidway-s5600/quidway-s5600_operation-manual_169841680.webp)
Operation Manual - DHCP
Quidway S5600 Series Ethernet Switches-Release 1510
Chapter 4 DHCP Snooping Configuration
Huawei Technologies Proprietary
4-1
Chapter 4 DHCP Snooping Configuration
4.1 Introduction to DHCP Snooping
For the sake of security, the IP addresses used by online DHCP clients need to be
tracked for the administrator to verify the corresponding relationship between the IP
addresses the DHCP clients obtained from DHCP servers and the MAC addresses of
the DHCP clients.
z
Layer 3 switches can track DHCP client IP addresses through DHCP relay.
z
Layer 2 switches can track DHCP client IP addresses through the DHCP
snooping function, which listens DHCP broadcast packets.
When an unauthorized DHCP server exists in the network, a DHCP client may obtains
an illegal IP address. To ensure that the DHCP clients obtain IP addresses from valid
DHCP servers, you can specify a port to be a trusted port or an untrusted port by the
DHCP snooping function.
z
Trusted ports can be used to connect DHCP servers or ports of other switches.
Untrusted ports can be used to connect DHCP clients or networks.
z
Untrusted ports drop the DHCP-ACK and DHCP-OFFER packets received from
DHCP servers. Trusted ports forward any received DHCP packets to ensure that
DHCP clients can obtain IP addresses from valid DHCP servers.
Figure 4-1 illustrates a typical network diagram for DHCP snooping application, where
Switch A is an S5600 series switch.
Internet
DHCP client
DHCP client
DHCP client
Ethernet
DHCP client
Switch A (DHCP snooping)
DHCP server
Switch B (DHCP relay)
Internet
Ethernet
Ethernet
Internet
DHCP client
DHCP client
DHCP client
Ethernet
DHCP client
Switch A (DHCP snooping)
DHCP server
Switch B (DHCP relay)
Internet
Ethernet
Internet
DHCP client
DHCP client
DHCP client
Ethernet
DHCP client
Switch A (DHCP snooping)
DHCP server
Switch B (DHCP relay)
Internet
Ethernet
Ethernet
Ethernet
Figure 4-1
Typical network diagram for DHCP snooping application
Figure 4-2 illustrates the interaction between a DHCP client and a DHCP server.