Chapter 23 IP Source Guard
MGS-3712/MGS-3012F User’s Guide
186
Trusted ports are connected to DHCP servers or other switches. The Switch discards DHCP
packets from trusted ports only if the rate at which DHCP packets arrive is too high. The
Switch learns dynamic bindings from trusted ports.
"
If DHCP is enabled and there are no trusted ports, DHCP requests will not
succeed.
Untrusted ports are connected to subscribers. The Switch discards DHCP packets from
untrusted ports in the following situations:
• The packet is a DHCP server packet (for example, OFFER, ACK, or NACK).
• The source MAC address and source IP address in the packet do not match any of the
current bindings.
• The packet is a RELEASE or DECLINE packet, and the source MAC address and source
port do not match any of the current bindings.
• The rate at which DHCP packets arrive is too high.
23.1.1.2 DHCP Snooping Database
The Switch stores the binding table in volatile memory. If the Switch restarts, it loads static
bindings from permanent memory but loses the dynamic bindings, in which case the devices in
the network have to send DHCP requests again. As a result, it is recommended you configure
the DHCP snooping database.
The DHCP snooping database maintains the dynamic bindings for DHCP snooping and ARP
inspection in a file on an external TFTP server. If you set up the DHCP snooping database, the
Switch can reload the dynamic bindings from the DHCP snooping database after the Switch
restarts.
You can configure the name and location of the file on the external TFTP server. The file has
the following format:
Figure 102
DHCP Snooping Database File Format
The <initial-checksum> helps distinguish between the bindings in the latest update and the
bindings from previous updates. Each binding consists of 72 bytes, a space, and another
checksum that is used to validate the binding when it is read. If the calculated checksum is not
equal to the checksum in the file, that binding and all others after it are ignored.
<initial-checksum>
TYPE DHCP-SNOOPING
VERSION 1
BEGIN
<binding-1> <checksum-1>
<binding-2> <checksum-1-2>
...
...
<binding-n> <checksum-1-2-..-n>
END
Содержание MGS-3712
Страница 2: ......
Страница 7: ...Safety Warnings MGS 3712 MGS 3012F User s Guide 7 ...
Страница 8: ...Safety Warnings MGS 3712 MGS 3012F User s Guide 8 ...
Страница 20: ...Table of Contents MGS 3712 MGS 3012F User s Guide 20 ...
Страница 28: ...List of Tables MGS 3712 MGS 3012F User s Guide 28 ...
Страница 30: ...30 ...
Страница 38: ...Chapter 2 Hardware Installation and Connection MGS 3712 MGS 3012F User s Guide 38 ...
Страница 50: ...50 ...
Страница 70: ...Chapter 6 System Status and Port Statistics MGS 3712 MGS 3012F User s Guide 70 ...
Страница 82: ...Chapter 7 Basic Setting MGS 3712 MGS 3012F User s Guide 82 ...
Страница 84: ...84 ...
Страница 132: ...Chapter 15 Link Aggregation MGS 3712 MGS 3012F User s Guide 132 ...
Страница 142: ...Chapter 17 Port Security MGS 3712 MGS 3012F User s Guide 142 ...
Страница 148: ...Chapter 18 Classifier MGS 3712 MGS 3012F User s Guide 148 Figure 80 Classifier Example ...
Страница 153: ...Chapter 19 Policy Rule MGS 3712 MGS 3012F User s Guide 153 Figure 83 Policy Example ...
Страница 154: ...Chapter 19 Policy Rule MGS 3712 MGS 3012F User s Guide 154 ...
Страница 169: ...Chapter 21 Multicast MGS 3712 MGS 3012F User s Guide 169 Figure 96 MVR Group Configuration Example ...
Страница 170: ...Chapter 21 Multicast MGS 3712 MGS 3012F User s Guide 170 ...
Страница 184: ...Chapter 22 Authentication Accounting MGS 3712 MGS 3012F User s Guide 184 ...
Страница 214: ...Chapter 25 Two Rate Three Color Marker MGS 3712 MGS 3012F User s Guide 214 ...
Страница 215: ...215 PART IV IP Application Static Route 217 DHCP 221 ...
Страница 216: ...216 ...
Страница 220: ...Chapter 26 Static Route MGS 3712 MGS 3012F User s Guide 220 ...
Страница 227: ...Chapter 27 DHCP MGS 3712 MGS 3012F User s Guide 227 Figure 134 DHCP Relay for Two VLANs Configuration Example ...
Страница 228: ...Chapter 27 DHCP MGS 3712 MGS 3012F User s Guide 228 ...
Страница 230: ...230 ...
Страница 256: ...Chapter 30 Diagnostic MGS 3712 MGS 3012F User s Guide 256 ...
Страница 260: ...Chapter 31 Syslog MGS 3712 MGS 3012F User s Guide 260 ...
Страница 273: ...273 PART VI Troubleshooting Product Specifications Troubleshooting 275 Product Specifications 279 ...
Страница 274: ...274 ...
Страница 278: ...Chapter 36 Troubleshooting MGS 3712 MGS 3012F User s Guide 278 ...
Страница 285: ...285 PART VII Appendices and Index Common Services 287 Legal Information 291 Customer Support 295 Index 301 ...
Страница 286: ...286 ...
Страница 290: ...Appendix A Common Services MGS 3712 MGS 3012F User s Guide 290 ...
Страница 294: ...Appendix B Legal Information MGS 3712 MGS 3012F User s Guide 294 ...
Страница 308: ...Index MGS 3712 MGS 3012F User s Guide 308 ...