92
Advanced Settings
security of an existing DHCP infrastructure. When DHCP servers are allocating IP
addresses to the clients on the LAN, DHCP snooping can be configured on LAN switches
to harden the security on the LAN to allow only clients with specific IP/MAC addresses to
have access to the network.
Ports which are connected to DHCP servers and other DHCP Snooping devices need to
be configured as trusted ports and other ports need to be configured as untrusted ports,
so that DHCP clients can only obtain IP addresses from legal DHCP clients.
Untrusted Port: The port is used for connecting to terminal devices. Clients on this
kind of ports can only send DHCP request packets.
Trusted Port: Port or Trunk port connecting to legal DHCP servers.
The switch can establish a user binding list via DHCP snooping. Once a client connected
to an untrusted port obtains a legal IP address, the switch will automatically display an
entry (including client IP/ MAC address, port number/belonging VLAN, lease time, etc.) in
the user binding list for MAC source defense and Ping test.
DHCP Option 82
As Option 82 records location info of DHCP clients, you can use it to locate DHCP clients,
thus implementing security and accounting control for clients.
The DHCP Snooping function of this device supports Option 82 and two sub-options are
available: circuit ID sub-option and remote ID sub-option. By default, the circuit ID
sub-option is made up of port belonging VLAN ID of received DHCP client request packets
and port number. The remote ID sub-option is made up of the MAC address of the DHCP
Snooping device which receives DHCP client request packets.
When the switch receives DHCP request packets, it will process these packets according
to whether Option 82 included, processing strategy of user configuration and user-defined
option status, and then forward them to the DHCP server. Three strategies are available:
replace, keep and drop.
Option 82
included
or not
Processing
Strategy
User-defined
Option
Status
Description
Yes
Replace
Enable
Use user-defined circuit ID sub-option and
remote ID sub-option to fill Option 82. Then
the previous Option 82 information will be
replaced and forwarded.
Содержание G3210P
Страница 1: ......
Страница 6: ...Product Overview Package Contents Physical Appearance...
Страница 127: ...122 Advanced Settings 2 Click Save on the pop out dialog 3 Select a path to save files to your local PC and click Save...
Страница 129: ...Appendix Technical Specifications Default Settings Safety and Emission Statement...