
213
NS3503-16P-4C User Manual
the switch forwards the packet only if the corresponding entry is found in the
binding table.
If the DHCP packet is from a client, such as a DISCOVER, REQUEST, INFORM,
DECLINE or RELEASE message, the packet is forwarded if MAC address
verification is disabled. However, if MAC address verification is enabled, then the
packet will only be forwarded if the client’s hardware address stored in the DHCP
packet is the same as the source MAC address in the Ethernet header.
If the DHCP packet is not a recognizable type, it is dropped.
If a DHCP packet from a client passes the filtering criteria above, it will only be forwarded to trusted
ports in the same VLAN.
If a DHCP packet is from server is received on a trusted port, it will be forwarded to both trusted and
untrusted ports in the same VLAN.
If the DHCP snooping is globally disabled, all dynamic bindings are removed from the binding table.
Additional considerations when the switch itself is a DHCP client – The port(s) through which the
switch submits a client request to the DHCP server must be configured as trusted. Note that the
switch will not add a dynamic entry for itself to the binding table when it receives an ACK message
from a DHCP server. Also, when the switch sends out DHCP client packets for itself, no filtering
takes place. However, when the switch receives any messages from a DHCP server, any packets
received from untrusted ports are dropped.
4.9.7.2 Global Setting
DHCP Snooping is used to block intruder on the untrusted ports of switch when it tries to intervene by
injecting a bogus DHCP reply packet to a legitimate conversation between the DHCP client and server.
Configure DHCP Snooping on this page. The DHCP Snooping Setting and Information screens in Figure
4-9-33 and Figure 4-9-34 appear.
Figure 4-9-33 DHCP Snooping Setting Page Screenshot
The page includes the following fields:
Object
Description
DHCP Snooping
Indicates the DHCP snooping mode operation. Possible modes are:
Enabled: Enable DHCP snooping mode operation.
When enable DHCP snooping mode operation, the request DHCP messages
will be forwarded to trusted ports and only allowed reply packets from trusted
ports.
Содержание NS3503-16P-4C
Страница 1: ...NS3503 16P 4C User Manual P N 1073221 REV A ISS 08SEP16 ...
Страница 143: ...141 NS3503 16P 4C User Manual Figure 4 7 3 Multicast Service Figure 4 7 4 Multicast Flooding ...
Страница 302: ...NS3503 16P 4C User Manual 300 The screen in Figure 4 16 5 appears Figure 4 16 5 PoE Schedule Screenshot ...