D-Link DWS-4026 [251/741] Configuring dhcp snooping

D-Link DWS-4026 [251/741] Configuring dhcp snooping
ConfiguringDHCPSnooping
D-Link UnifiedWiredandWirelessAccessSystem
November2011 Page251
DLinkUWSUserManual
ConfiguringDHCPSnooping
DHCPsnoopingisasecurityfeaturethatmonitorsDHCPmessagesbetweenaDHCPclientandDHCPserversto
filterharmfulDHCPmessagesandtobuildabindingsdatabaseof{MACaddress,IPaddress,VLANID,port}
tuplesthatareconsideredauthorized.YoucanenableDHCPsnoopinggloballyandonspecificVLANs,and
c
onfigureportswithintheVLANtobetrustedoruntrusted.DHCPserversmustbereachedthroughtrusted
ports.DHCPsnoopingenforcesthefollowingsecurityrules:
•DHCPpacketsfromaDHCPserver(DHCPOFFER,DHCPACK,DHCPNAK,DHCPRELEASEQUERY)aredropped
ifreceivedonanuntrustedport.
•DHCPRELEASEandDHCPDECLINEmessagesaredroppedifdestinedfo
raMACaddressinthesnooping
database,butthecorrespondingIPaddressinthesnoopingdatabaseisdifferentthantheinterfacewhere
themessagewasreceived.
•Onuntrustedinterfaces,theswitchdropsDHCPpack etswhosesourceMACaddressdoesnotmatchthe
clienthardwareaddress.Thisfeatureisaconfigurableoptio
n.
ThehardwareidentifiesallincomingDHCPpacketsonportswhereDHCPsnoopingisenabled.DHCPsnooping
isenabledonaportif(a)DHCPsnoopingisenabledglobally,and(b)theportisamemberofaVLANwhere
DHCPsnoopingisenabled.Onuntrustedports,thehardwaretrapsallinc
omingDHCPpacketstotheCPU.On
trustedports,thehardwareforwardsclientmessagesandcopiesservermessagestotheCPUsothatDHCP
snoopingcanlearnthebinding.
GlobalDHCPSnoopingConfiguration
ToaccesstheDHCPSnoopingConfigurationpage,clickLAN>L2Features>DHCPSnooping>Configurationin
thenavigationtree.
Figure156:DHCPSnoopingConfiguration
•ClickSubmittoapplythenewconfigurationandcausethechangetotakeeffect.Thesechangeswillnot
beretainedacrossapowercycleunlessaSa
veconfigurationisperformed.
Table137:DHCPSnoopingConfiguration
Field Description
DHCPSnoopingMode EnablesordisablestheDHCPSnoopingfeature.ThedefaultisDisable.
MACAddressValidation EnablesordisablesthevalidationofsenderMACAddressforDHCPSnooping.
ThedefaultisEnable.

Содержание

Похожие устройства

Скачать