Chapter 26 IP Source Guard
MES-3528 User’s Guide
224
26.1.1 DHCP Snooping Overview
Use DHCP snooping to filter unauthorized DHCP packets on the network and to
build the binding table dynamically. This can prevent clients from getting IP
addresses from unauthorized DHCP servers.
26.1.1.1 Trusted vs. Untrusted Ports
Every port is either a trusted port or an untrusted port for DHCP snooping. This
setting is independent of the trusted/untrusted setting for ARP inspection. You can
also specify the maximum number for DHCP packets that each port (trusted or
untrusted) can receive each second.
Trusted ports are connected to DHCP servers or other switches. The Switch
discards DHCP packets from trusted ports only if the rate at which DHCP packets
arrive is too high. The Switch learns dynamic bindings from trusted ports.
Note: If DHCP is enabled and there are no trusted ports, DHCP requests will not
succeed.
Untrusted ports are connected to subscribers. The Switch discards DHCP packets
from untrusted ports in the following situations:
• The packet is a DHCP server packet (for example, OFFER, ACK, or NACK).
• The source MAC address and source IP address in the packet do not match any
of the current bindings.
• The packet is a RELEASE or DECLINE packet, and the source MAC address and
source port do not match any of the current bindings.
• The rate at which DHCP packets arrive is too high.
26.1.1.2 DHCP Snooping Database
The Switch stores the binding table in volatile memory. If the Switch restarts, it
loads static bindings from permanent memory but loses the dynamic bindings, in
which case the devices in the network have to send DHCP requests again. As a
result, it is recommended you configure the DHCP snooping database.
The DHCP snooping database maintains the dynamic bindings for DHCP snooping
and ARP inspection in a file on an external TFTP server. If you set up the DHCP
snooping database, the Switch can reload the dynamic bindings from the DHCP
snooping database after the Switch restarts.
Содержание MES-3528 -
Страница 2: ......
Страница 8: ...Safety Warnings MES 3528 User s Guide 8 ...
Страница 22: ...22 ...
Страница 32: ...Chapter 2 Hardware Installation and Connection MES 3528 User s Guide 32 ...
Страница 42: ...Chapter 3 Hardware Overview MES 3528 User s Guide 42 ...
Страница 44: ...44 ...
Страница 60: ...Chapter 5 Initial Setup Example MES 3528 User s Guide 60 ...
Страница 76: ...Chapter 7 System Status and Port Statistics MES 3528 User s Guide 76 ...
Страница 88: ...Chapter 8 Basic Setting MES 3528 User s Guide 88 ...
Страница 90: ...90 ...
Страница 109: ...Chapter 9 VLAN MES 3528 User s Guide 109 Figure 57 Port Based VLAN Setup Port Isolation ...
Страница 114: ...Chapter 10 Static MAC Forward Setup MES 3528 User s Guide 114 ...
Страница 146: ...Chapter 14 Bandwidth Control MES 3528 User s Guide 146 ...
Страница 160: ...Chapter 17 Link Aggregation MES 3528 User s Guide 160 ...
Страница 168: ...Chapter 19 Port Security MES 3528 User s Guide 168 ...
Страница 180: ...Chapter 21 Policy Rule MES 3528 User s Guide 180 ...
Страница 192: ...Chapter 23 VLAN Stacking MES 3528 User s Guide 192 ...
Страница 231: ...Chapter 26 IP Source Guard MES 3528 User s Guide 231 Figure 120 DHCP Snooping ...
Страница 248: ...Chapter 26 IP Source Guard MES 3528 User s Guide 248 ...
Страница 257: ...257 PART IV IP Application Static Route 259 Differentiated Services 263 DHCP 267 ...
Страница 258: ...258 ...
Страница 262: ...Chapter 29 Static Route MES 3528 User s Guide 262 ...
Страница 274: ...Chapter 31 DHCP MES 3528 User s Guide 274 ...
Страница 276: ...276 ...
Страница 284: ...Chapter 32 Maintenance MES 3528 User s Guide 284 ...
Страница 306: ...Chapter 33 Access Control MES 3528 User s Guide 306 ...
Страница 312: ...Chapter 35 Syslog MES 3528 User s Guide 312 ...
Страница 320: ...Chapter 36 Cluster Management MES 3528 User s Guide 320 ...
Страница 324: ...Chapter 37 MAC Table MES 3528 User s Guide 324 ...
Страница 329: ...329 PART VI Troubleshooting Product Specifications Troubleshooting 331 Product Specifications 335 ...
Страница 330: ...330 ...
Страница 342: ...Chapter 41 Product Specifications MES 3528 User s Guide 342 ...
Страница 343: ...343 PART VII Appendices and Index Changing a Fuse 345 Common Services 347 Legal Information 351 Index 355 ...
Страница 344: ...344 ...
Страница 346: ...Appendix A Changing a Fuse MES 3528 User s Guide 346 ...
Страница 354: ...Appendix C Legal Information MES 3528 User s Guide 354 ...
Страница 364: ...Index MES 3528 User s Guide 364 ...