68
Table of Contents
Linksys
68
Table of Contents
Linksys
Overview
DHCP snooping provides a security mechanism to prevent receiving false DHCP
response packets and to log DHCP addresses It does this by treating ports on
the device as either trusted or untrusted
A trusted port is a port that is connected to a DHCP server and is allowed to
assign DHCP addresses DHCP messages received on trusted ports are allowed
to pass through the device
An untrusted port is a port that is not allowed to assign DHCP addresses By
default, all ports are considered untrusted until you declare them trusted in the
DCHP Snooping Interface Settings page
Option 82
Option 82 (DHCP Relay Agent Information Option) passes port and agent
information to a central DHCP server, indicating where an assigned IP address
physically connects to the network
The main goal of option 82 is to help to the DHCP server select the best IP
subnet (network pool) from which to obtain an IP address
The following Option 82 options are available on the device:
•
DHCP Passthrough - Forward or reject DHCP packets that contain Option
82 information from untrusted ports On trusted ports, DHCP packets
containing Option 82 information are always forwarded
The following describes how DHCP request packets are handled when DHCP
snooping is disabled
Option 82
Insertion
Disabled
DHCP Relay VLAN with IP
Address
DHCP Relay VLAN without IP
Address
Packet arrives
without
Option 82
Packet arrives
with Option 82
Packet arrives
without
Option 82
Packet arrives
with Option 82
Packet is
sent without
Option 82
Packet is sent
with original
Option 82
Relay -
Discards
Option 82
Bridge – Packet
is sent without
Option 82
If reply
originates in
the device,
the packet is
sent without
Option 82 If
reply does not
originate in the
device
DHCP Snooping Binding Database
DHCP Snooping builds a database (known as the DHCP Snooping Binding
database) derived from information taken from DHCP packets entering the
device through trusted ports
The DHCP Snooping Binding database contains the following data: input port,
input VLAN, MAC address of the client, and IP address of the client if it exists
DHCP Trusted Ports
Ports can be either DHCP trusted or untrusted By default, all ports are
untrusted To create a port as trusted, use the DHCP Snooping Trusted Interface
page Packets from these ports are automatically forwarded Packets from
trusted ports are used to create the Binding database and are handled as
described below
If DHCP Snooping is not enabled, all ports are trusted by default
How the DHCP Snooping Binding Database is Built
The following describes how the device handles DHCP packets when both
the DHCP client and DHCP server are trusted The DHCP Snooping Binding
database is built in this process
Содержание Smart Switch LGS3XX
Страница 1: ...Smart Switch LGS3XX User Guide ...