C
HAPTER
4
| Configuring the Switch
Configuring Security
– 107 –
C
ONFIGURING
DHCP
S
NOOPING
Use the DHCP Snooping Configuration page to filter IP traffic on insecure
ports for which the source address cannot be identified via DHCP snooping.
The addresses assigned to DHCP clients on insecure ports can be carefully
controlled using the dynamic bindings registered with DHCP Snooping (or
using the static bindings configured with IP Source Guard). DHCP snooping
allows a switch to protect a network from rogue DHCP servers or other
devices which send port-related information to a DHCP server. This
information can be useful in tracking an IP address back to a physical port.
P
ATH
Advanced Configuration, Security, Network, DHCP, Snooping
C
OMMAND
U
SAGE
DHCP Snooping Process
◆
Network traffic may be disrupted when malicious DHCP messages are
received from an outside source. DHCP snooping is used to filter DHCP
messages received on a non-secure interface from outside the network
or fire wall. When DHCP snooping is enabled globally and enabled on a
VLAN interface, DHCP messages received on an untrusted interface
from a device not listed in the DHCP snooping table will be dropped.
◆
Table entries are only learned for trusted interfaces. An entry is added
or removed dynamically to the DHCP snooping table when a client
receives or releases an IP address from a DHCP server. Each entry
includes a MAC address, IP address, lease time, VLAN identifier, and
port identifier.
◆
When DHCP snooping is enabled, DHCP messages entering an
untrusted interface are filtered based upon dynamic entries learned via
DHCP snooping.
◆
Filtering rules are implemented as follows:
■
If the global DHCP snooping is disabled, all DHCP packets are
forwarded.
■
If DHCP snooping is enabled globally, all DHCP packets are
forwarded for a
trusted
port. If the received packet is a DHCP ACK
message, a dynamic DHCP snooping entry is also added to the
binding table.
■
If DHCP snooping is enabled globally, but the port is
not trusted
, it
is processed as follows:
■
If the DHCP packet is a reply packet from a DHCP server
(including OFFER, ACK or NAK messages), the packet is
dropped.
■
If a DHCP DECLINE or RELEASE message is received from a
client, the switch forwards the packet only if the corresponding
entry is found in the binding table.
■
If a DHCP DISCOVER, REQUEST or INFORM message is received
from a client, the packet is forwarded.
Содержание GEP-5070
Страница 1: ...GEP 5070 48 GE PoE Plus 2 GE SFP L2 Managed Switch User Manual V1 0...
Страница 2: ......
Страница 4: ......
Страница 6: ...ABOUT THIS GUIDE 6...
Страница 18: ...FIGURES 18...
Страница 20: ...TABLES 20...
Страница 22: ...SECTION I Getting Started 22...
Страница 34: ...SECTION II Web Configuration 34...
Страница 217: ...CHAPTER 4 Configuring the Switch Configuring sFlow 217 Figure 96 sFlow Configuration...
Страница 218: ...CHAPTER 4 Configuring the Switch Configuring sFlow 218...
Страница 286: ...CHAPTER 6 Performing Basic Diagnostics Running Cable Diagnostics 286...
Страница 291: ...CHAPTER 7 Performing System Maintenance Managing Configuration Files 291 Figure 157 Configuration Upload...
Страница 292: ...CHAPTER 7 Performing System Maintenance Managing Configuration Files 292...
Страница 294: ...SECTION III Appendices 294...
Страница 312: ...GLOSSARY 312...
Страница 317: ......
Страница 318: ...GEP 5070 E042013 ST R01...