Netis ST3326(ST-3302) [73/118] Dhcp snooping configuration

73
expires.
If the DHCP client fails to update its IP address lease when half of the lease time elapses, it will
update its IP address lease by broadcasting a DHCP-REQUEST packet to the DHCP servers again
when seven-eighths of the lease time elapses. The DHCP server performs the same operations as
those described above.
DHCP Packet Format
DHCP has eight types of packets. They have the same format, but the values of some fields in the
packets are different. The DHCP packet format is based on that of the BOOTP packets.
Protocol Specification
Protocol specifications related to DHCP include:
RFC2131: Dynamic Host Configuration Protocol
RFC2132: DHCP Options and BOOTP Vendor Extensions
RFC1542: Clarifications and Extensions for the Bootstrap Protocol
RFC3046: DHCP Relay Agent Information option
DHCP Snooping Configuration
Introduction to DHCP Snooping
For the sake of security, the IP addresses used by online DHCP clients need to be tracked for the
administrator to verify the corresponding relationship between the IP addresses the DHCP clients
obtained from DHCP servers and the MAC addresses of the DHCP clients.
Layer 2 switches can track DHCP client IP addresses through the DHCP snooping function, which
listens DHCP broadcast packets.
Introduction to DHCP Snooping Trusted/Untrusted Ports
When an unauthorized DHCP server exists in the network, a DHCP client may obtains an illegal IP
address. To ensure that the DHCP clients obtain IP addresses from valid DHCP servers, The
switches can specify a port to be a trusted port or an untrusted port by the DHCP snooping
function.
Trusted: A trusted port is connected to an authorized DHCP server directly or indirectly. It
forwards DHCP messages to guarantee that DHCP clients can obtain valid IP addresses.
Untrusted: An untrusted port is connected to an unauthorized DHCP server. The DHCP-ACK
or DHCP-OFFER packets received from the port are discarded, preventing DHCP clients from
receiving invalid IP addresses.
Overview of DHCP-Snooping Option 82
Introduction to Option 82

Содержание

Скачать