Chapter 26 IP Source Guard
GS2210 Series User’s Guide
253
26.19 Technical Reference
This sect ion pr ovides t echnical backgr ound infor m at ion on t he t opics discussed in t his chapt er.
26.19.1 DHCP Snooping Overview
Use DHCP snooping t o filt er unaut hor ized DHCP packet s on t he net w or k and t o build t he binding
t able dynam ically. This can pr event client s fr om get t ing I P addr esses fr om unaut hor ized DHCP
ser ver s.
26.19.1.1 Trusted vs. Untrusted Ports
Ever y por t is eit her a t r ust ed por t or an unt r ust ed por t for DHCP snooping. This set t ing is
independent of t he t r ust ed/ unt r ust ed set t ing for ARP inspect ion. You can also specify t he m axim um
num ber for DHCP packet s t hat each por t ( t r ust ed or unt r ust ed) can r eceive each second.
Tr ust ed por t s ar e connect ed t o DHCP ser ver s or ot her sw it ches. The Sw it ch discar ds DHCP packet s
fr om t r ust ed por t s only if t he rat e at w hich DHCP packet s ar r ive is t oo high. The Sw it ch lear ns
dynam ic bindings fr om t r ust ed por t s.
Not e: I f DHCP is enabled and t her e ar e no t r ust ed por t s, DHCP r equest s w ill not succeed.
Unt r ust ed por t s are connect ed t o subscr iber s. The Swit ch discar ds DHCP packet s fr om unt r ust ed
por t s in t he follow ing sit uat ions:
•
The packet is a DHCP ser ver packet ( for exam ple, OFFER, ACK, or NACK) .
•
The sour ce MAC addr ess and sour ce I P addr ess in t he packet do not m at ch any of t he cur r ent
bindings.
*
Set t ings in t his r ow apply t o all por t s.
Use t his r ow only if you want t o m ake som e set t ings t he sam e for all por t s. Use t his r ow
fir st t o set t he com m on set t ings and t hen m ake adj ust m ent s on a por t - by- por t basis.
Note: Changes in this row are copied to all the ports as soon as you make them.
Trust ed st at e
Select w het her t his por t is a t r ust ed por t ( Tr u st e d) or an unt r ust ed por t ( U n t r u st e d) .
Tr ust ed port s ar e connect ed t o DHCPv 6 ser ver s or ot her sw it ches.
Unt r ust ed por t s ar e connect ed t o subscr iber s, and t he Sw it ch discar ds DHCPv 6 packet s
fr om unt rust ed por t s in t he follow ing sit uat ions:
•
The packet is a DHCPv 6 ser ver packet ( for ex am ple, ADVERTI SE, REPLY, or RELAY-
REPLY) .
•
The sour ce MAC addr ess and sour ce I P address in t he packet do not m at ch any of t he
cur r ent bindings.
Apply
Click Apply t o save your changes t o t he Sw it ch’s r un- t im e m em or y. The Sw it ch loses
t hese changes if it is t ur ned off or loses pow er, so use t he Sa ve link on t he t op nav igat ion
panel t o save your changes t o t he non- volat ile m em or y w hen you ar e done configur ing.
Cancel
Click t his t o r eset t he values in t his screen t o t heir last - saved values.
Table 117
Advanced Applicat ion > I P Sour ce Guar d > I Pv6 DHCP Tr ust Set up
LABEL
DESCRIPTION
Содержание GS2210-24
Страница 18: ...18 PART I User s Guide ...
Страница 33: ...33 PART II Technical Reference ...
Страница 110: ...Chapter 9 VLAN GS2210 Series User s Guide 110 Figure 83 Advanced Application VLAN Port Based VLAN Setup All Connected ...
Страница 111: ...Chapter 9 VLAN GS2210 Series User s Guide 111 Figure 84 Advanced Application VLAN Port Based VLAN Setup Port Isolation ...
Страница 178: ...Chapter 21 Classifier GS2210 Series User s Guide 178 Figure 127 Classifier Example ...
Страница 405: ...Chapter 51 Configure Clone GS2210 Series User s Guide 405 Figure 286 Management Configure Clone ...
Страница 433: ...Appendix D Legal Information GS2210 Series User s Guide 433 Environmental Product Declaration ...