
Chapter 26 IP Source Guard
XGS-4526/4528F/4728F User’s Guide
260
26.1.1 DHCP Snooping Overview
Use DHCP snooping to filter unauthorized DHCP packets on the network and to
build the binding table dynamically. This can prevent clients from getting IP
addresses from unauthorized DHCP servers.
26.1.1.1 Trusted vs. Untrusted Ports
Every port is either a trusted port or an untrusted port for DHCP snooping. This
setting is independent of the trusted/untrusted setting for ARP inspection. You can
also specify the maximum number for DHCP packets that each port (trusted or
untrusted) can receive each second.
Trusted ports are connected to DHCP servers or other switches. The Switch
discards DHCP packets from trusted ports only if the rate at which DHCP packets
arrive is too high. The Switch learns dynamic bindings from trusted ports.
Note: The Switch will drop all DHCP requests if you enable DHCP snooping and there
are no trusted ports.
Untrusted ports are connected to subscribers. The Switch discards DHCP packets
from untrusted ports in the following situations:
• The packet is a DHCP server packet (for example, OFFER, ACK, or NACK).
• The source MAC address and source IP address in the packet do not match any
of the current bindings.
• The packet is a RELEASE or DECLINE packet, and the source MAC address and
source port do not match any of the current bindings.
• The rate at which DHCP packets arrive is too high.
26.1.1.2 DHCP Snooping Database
The Switch stores the binding table in volatile memory. If the Switch restarts, it
loads static bindings from permanent memory but loses the dynamic bindings, in
which case the devices in the network have to send DHCP requests again. As a
result, it is recommended you configure the DHCP snooping database.
The DHCP snooping database maintains the dynamic bindings for DHCP snooping
and ARP inspection in a file on an external TFTP server. If you set up the DHCP
snooping database, the Switch can reload the dynamic bindings from the DHCP
snooping database after the Switch restarts.
Содержание XGS-4528F
Страница 2: ......
Страница 8: ...Safety Warnings XGS 4526 4528F 4728F User s Guide 8...
Страница 24: ...Table of Contents XGS 4526 4528F 4728F User s Guide 24...
Страница 25: ...25 PART I User s Guide...
Страница 26: ...26...
Страница 32: ...Chapter 1 Getting to Know Your Switch XGS 4526 4528F 4728F User s Guide 32...
Страница 36: ...Chapter 2 Hardware Installation and Connection XGS 4526 4528F 4728F User s Guide 36...
Страница 93: ...93 PART II Technical Reference...
Страница 94: ...94...
Страница 100: ...Chapter 7 System Status and Port Statistics XGS 4526 4528F 4728F User s Guide 100...
Страница 116: ...Chapter 8 Basic Setting XGS 4526 4528F 4728F User s Guide 116...
Страница 136: ...Chapter 9 VLAN XGS 4526 4528F 4728F User s Guide 136...
Страница 140: ...Chapter 10 Static MAC Forward Setup XGS 4526 4528F 4728F User s Guide 140...
Страница 172: ...Chapter 14 Bandwidth Control XGS 4526 4528F 4728F User s Guide 172...
Страница 186: ...Chapter 17 Link Aggregation XGS 4526 4528F 4728F User s Guide 186...
Страница 196: ...Chapter 18 Port Authentication XGS 4526 4528F 4728F User s Guide 196...
Страница 214: ...Chapter 21 Policy Rule XGS 4526 4528F 4728F User s Guide 214...
Страница 258: ...Chapter 25 AAA XGS 4526 4528F 4728F User s Guide 258...
Страница 282: ...Chapter 26 IP Source Guard XGS 4526 4528F 4728F User s Guide 282...
Страница 314: ...Chapter 32 Error Disable XGS 4526 4528F 4728F User s Guide 314...
Страница 318: ...Chapter 33 Private VLAN XGS 4526 4528F 4728F User s Guide 318...
Страница 322: ...Chapter 34 Static Route XGS 4526 4528F 4728F User s Guide 322...
Страница 330: ...Chapter 36 RIP XGS 4526 4528F 4728F User s Guide 330...
Страница 386: ...Chapter 43 ARP Learning XGS 4526 4528F 4728F User s Guide 386...
Страница 396: ...Chapter 45 Maintenance XGS 4526 4528F 4728F User s Guide 396...
Страница 442: ...Chapter 49 Cluster Management XGS 4526 4528F 4728F User s Guide 442...
Страница 446: ...Chapter 50 MAC Table XGS 4526 4528F 4728F User s Guide 446...
Страница 450: ...Chapter 51 IP Table XGS 4526 4528F 4728F User s Guide 450...
Страница 454: ...Chapter 53 Routing Table XGS 4526 4528F 4728F User s Guide 454...
Страница 462: ...Chapter 55 Troubleshooting XGS 4526 4528F 4728F User s Guide 462...
Страница 472: ...Chapter 56 Product Specifications XGS 4526 4528F 4728F User s Guide 472...
Страница 480: ...Appendix B Legal Information XGS 4526 4528F 4728F User s Guide 480...