Configuration Guide
DHCP Snooping Configuration
DHCP Snooping TRUST port:
Because the packets for obtaining IP addresses through DHCP
are in the form of broadcast, some illegal servers may prevent users from obtaining IP
addresses, or even cheat and steal user information. To solve this problem, DHCP Snooping
classifies the ports into two types: TRUST port and UNTRUST port. The device forwards only
the DHCP reply packets received through the TRUST port while discarding all the DHCP reply
packets from the UNTRUST port. In this way, the illegal DHCP Server can be shielded by
setting the port connected to the legal DHCP Server as a TRUST port and other ports as
UNTRUST ports.
DHCP Snooping binding database:
By snooping the packets between the DHCP Clients and
the DHCP Server, DHCP Snooping combines the IP address, MAC address, VID, port and
lease time into a entry to form a DHCP Snooping user database.
DHCP Snooping checks the validity of DHCP packets that pass through the device, discards
illegal DHCP packets, and records user information to create a DHCP Snooping binding
database for ARP inspection and query. The following DHCP packets are considered illegal:
The DHCP reply packets received on the UNTRUST ports, including DHCPACK,
DHCPNACK, DHCPOFFER, etc.
DHCP Client values in the source MAC and DHCP packets are in different packets when
MAC check is enabled.
DHCPRELEASE packets whose port information is inconsistent with that in the the DHCP
Snooping binding database.
DHCP Snooping Information Option
Some network administrators want to assign IP address to current users upon their positions.
That is, they want to assign IP addresses to users according to the information on the network
equipments that users connect so that the switch can add the user-related device information
to the DHCP request packet in DHCP option way while performing DHCP Snooping. According
to RFC3046, the option number used is 82. You can obtain more user information by uploading
option82 to the content server. As a result, you can assign IP addresses accurately. The format
of option82 uploaded by DHCP Snooping is shown as follows and circuit ID includes two
formats, one for standard and extension format and the other is for DOT1X format:
Agent Circuit ID (Standard and extension format)
Содержание RG-S2900G-E Series
Страница 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Страница 91: ...Configuration Guide Configuring PoE Configuration ...
Страница 133: ...Configuration Guide EEE Configuration ...
Страница 319: ...Configuration Guide QinQ Configuration ...
Страница 408: ......
Страница 409: ...IP Routing Configuration 1 Static Route Configuration ...
Страница 412: ......
Страница 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Страница 621: ...Configuration Guide CPU Protection Configuration udp helper 180 4 dhcp client 180 4 lacp 180 4 ...
Страница 757: ......
Страница 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Страница 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Страница 901: ...Configuration Guide ERSPAN Configuration ...
Страница 902: ...Web based Configuration 1 Web based Configuration ...