Chapter 24 IP Source Guard
GS-2750 User’s Guide
196
Trusted ports are connected to DHCP servers or other switches. The Switch discards DHCP
packets from trusted ports only if the rate at which DHCP packets arrive is too high. The
Switch learns dynamic bindings from trusted ports.
"
The Switch will drop all DHCP requests if you enable DHCP snooping and
there are no trusted ports.
Untrusted ports are connected to subscribers. The Switch discards DHCP packets from
untrusted ports in the following situations:
• The packet is a DHCP server packet (for example, OFFER, ACK, or NACK).
• The source MAC address and source IP address in the packet do not match any of the
current bindings.
• The packet is a RELEASE or DECLINE packet, and the source MAC address and source
port do not match any of the current bindings.
• The rate at which DHCP packets arrive is too high.
24.1.1.2 DHCP Snooping Database
The Switch stores the binding table in volatile memory. If the Switch restarts, it loads static
bindings from permanent memory but loses the dynamic bindings, in which case the devices in
the network have to send DHCP requests again. As a result, it is recommended you configure
the DHCP snooping database.
The DHCP snooping database maintains the dynamic bindings for DHCP snooping and ARP
inspection in a file on an external TFTP server. If you set up the DHCP snooping database, the
Switch can reload the dynamic bindings from the DHCP snooping database after the Switch
restarts.
You can configure the name and location of the file on the external TFTP server. The file has
the following format:
Figure 94
DHCP Snooping Database File Format
The <initial-checksum> helps distinguish between the bindings in the latest update and the
bindings from previous updates. Each binding consists of 72 bytes, a space, and another
checksum that is used to validate the binding when it is read. If the calculated checksum is not
equal to the checksum in the file, that binding and all others after it are ignored.
<initial-checksum>
TYPE DHCP-SNOOPING
VERSION 1
BEGIN
<binding-1> <checksum-1>
<binding-2> <checksum-1-2>
...
...
<binding-n> <checksum-1-2-..-n>
END
Содержание GS-2750
Страница 2: ......
Страница 7: ...Safety Warnings GS 2750 User s Guide 7 This product is recyclable Dispose of it properly ...
Страница 8: ...Safety Warnings GS 2750 User s Guide 8 ...
Страница 26: ...List of Figures GS 2750 User s Guide 26 ...
Страница 32: ...32 ...
Страница 40: ...Chapter 2 Hardware Installation and Connection GS 2750 User s Guide 40 ...
Страница 48: ...48 ...
Страница 58: ...Chapter 4 The Web Configurator GS 2750 User s Guide 58 ...
Страница 64: ...Chapter 5 Initial Setup Example GS 2750 User s Guide 64 ...
Страница 70: ...Chapter 6 System Status and Port Statistics GS 2750 User s Guide 70 ...
Страница 82: ...Chapter 7 Basic Setting GS 2750 User s Guide 82 ...
Страница 84: ...84 ...
Страница 115: ...Chapter 11 Spanning Tree Protocol GS 2750 User s Guide 115 Figure 52 Advanced Application Spanning Tree Protocol MSTP ...
Страница 120: ...Chapter 11 Spanning Tree Protocol GS 2750 User s Guide 120 ...
Страница 134: ...Chapter 15 Link Aggregation GS 2750 User s Guide 134 ...
Страница 144: ...Chapter 17 Port Security GS 2750 User s Guide 144 ...
Страница 155: ...Chapter 19 Policy Rule GS 2750 User s Guide 155 Figure 73 Policy Example example ...
Страница 156: ...Chapter 19 Policy Rule GS 2750 User s Guide 156 ...
Страница 160: ...Chapter 20 Queuing Method GS 2750 User s Guide 160 ...
Страница 166: ...Chapter 21 VLAN Stacking GS 2750 User s Guide 166 ...
Страница 194: ...Chapter 23 Authentication Accounting GS 2750 User s Guide 194 ...
Страница 219: ...219 PART IV IP Application Static Routing 221 RIP 223 Differentiated Services 225 DHCP 233 VRRP 243 ...
Страница 220: ...220 ...
Страница 232: ...Chapter 28 Differentiated Services GS 2750 User s Guide 232 ...
Страница 242: ...Chapter 29 DHCP GS 2750 User s Guide 242 ...
Страница 252: ...Chapter 30 VRRP GS 2750 User s Guide 252 ...
Страница 254: ...254 ...
Страница 278: ...Chapter 32 Access Control GS 2750 User s Guide 278 ...
Страница 280: ...Chapter 33 Diagnostic GS 2750 User s Guide 280 ...
Страница 284: ...Chapter 34 Syslog GS 2750 User s Guide 284 ...
Страница 298: ...Chapter 39 Routing Table GS 2750 User s Guide 298 ...
Страница 301: ...301 PART VI Product Specifications Product Specifications 303 ...
Страница 302: ...302 ...
Страница 309: ...309 PART VII Appendices and Index IP Addresses and Subnetting 311 Legal Information 319 Customer Support 323 Index 329 ...
Страница 310: ...310 ...
Страница 322: ...Appendix B Legal Information GS 2750 User s Guide 322 ...
Страница 328: ...Appendix C Customer Support GS 2750 User s Guide 328 ...