Web-based Configuration Guide
Security
98
7
Security
7.1
DHCP Snooping
7.1.1
Overview
The Dynamic Host Configuration Protocol (DHCP) snooping function allows a device to snoop DHCP packets
exchanged between clients and a server to record and monitor the IP address usage and filter out invalid DHCP
packets, including request packets from the clients and response packets from the server. DHCP snooping
records generated user data entries to serve security applications such as IP Source Guard.
7.1.2
Standalone Device Configuration
Choose
Local Device
>
Security
>
DHCP Snooping
.
Turn on the DHCP snooping function, select the port to be set as trusted ports on the port panel and click
Save
.
After DHCP Snooping is enabled, request packets from DHCP clients are forwarded only to trusted ports; for
response packets from DHCP servers, only those from trusted ports are forwarded.
Note
Generally, the uplink port connected to the DHCP server is configured as a trusted port.
Option 82 is used to enhance the DHCP server security and optimize the IP address assignment policy. Option
82 information will be carried in the DHCP request packet when Option 82 is turned on.
7.1.3
Batch Configuring Network Switches
Choose
Network
>
DHCP Snooping
.