Chapter 12
| Security Measures
DHCP Snooping
– 302 –
these packets. The switch can either drop the DHCP packets, keep the existing
information, or replace it with the switch’s relay information.
DHCP Snooping
Global Configuration
Use the Security > DHCP Snooping (Configure Global) page to enable DHCP
Snooping globally on the switch, or to configure MAC Address Verification.
Parameters
These parameters are displayed:
General
◆
DHCP Snooping Status –
Enables DHCP snooping globally. (Default: Disabled)
◆
DHCP Snooping MAC-Address Verification
– Enables or disables MAC
address verification. If the source MAC address in the Ethernet header of the
packet is not same as the client's hardware address in the DHCP packet, the
packet is dropped. (Default: Enabled)
Information
◆
DHCP Snooping Information Option Status
– Enables or disables DHCP
Option 82 information relay. (Default: Disabled)
◆
DHCP Snooping Information Option Sub-option Format
– Enables or
disables use of sub-type and sub-length fields in circuit-ID (CID) and remote-ID
(RID) in Option 82 information. (Default: Enabled)
◆
DHCP Snooping Information Option Remote ID
– Specifies the MAC address,
IP address, or arbitrary identifier of the requesting device (i.e., the switch in this
context).
■
MAC Address
– Inserts a MAC address in the remote ID sub-option for the
DHCP snooping agent (i.e., the MAC address of the switch’s CPU). This
attribute can be encoded in Hexadecimal or ASCII.
■
IP Address
– Inserts an IP address in the remote ID sub-option for the
DHCP snooping agent (i.e., the IP address of the management interface).
This attribute can be encoded in Hexadecimal or ASCII.
■
string
- An arbitrary string inserted into the remote identifier field.
(Range: 1-32 characters)
◆
DHCP Snooping Information Option Policy
– Specifies how to handle DHCP
client request packets which already contain Option 82 information.
■
Drop
– Drops the client’s request packet instead of relaying it.
■
Keep
– Retains the Option 82 information in the client request, and
forwards the packets to trusted ports.
■
Replace
– Replaces the Option 82 information circuit-id and remote-id
fields in the client’s request with information about the relay agent itself,
Содержание GEL-1061
Страница 14: ...Contents 14...
Страница 28: ...Section I Getting Started 28...
Страница 38: ...Chapter 1 Introduction System Defaults 38...
Страница 40: ...Section II Web Configuration 40...
Страница 60: ...Chapter 2 Using the Web Interface Navigating the Web Browser Interface 60...
Страница 164: ...Chapter 6 Address Table Settings Issuing MAC Address Traps 164...
Страница 192: ...Chapter 8 Congestion Control Storm Control 192...
Страница 204: ...Chapter 9 Class of Service Layer 3 4 Priority Settings 204...
Страница 216: ...Chapter 10 Quality of Service Attaching a Policy Map to a Port 216...
Страница 430: ...Chapter 14 Multicast Filtering MLD Snooping Snooping and Query for IPv4 430...
Страница 436: ...Chapter 15 IP Tools Address Resolution Protocol 436...
Страница 450: ...Chapter 16 IP Services Dynamic Host Configuration Protocol 450 Figure 301 Enabling Dynamic Provisioning via DHCP...
Страница 474: ...Section III Appendices 474...
Страница 492: ...Glossary 492...
Страница 500: ...E052016 ST R02 150200001416A...