Qtech QSW-2910-09T-POE-AC/DC [64/212] Dhcp snooping

Qtech QSW-2910-09T-POE-AC/DC [64/212] Dhcp snooping
+7(495) 797-3311 www.qtech.ru
Москва, Новозаводская ул., 18, стр. 1
64
Show option82 configuration
show dhcp option82
4.3 DHCP SNOOPING
It is a feature of level 2. It allow the switch to listen to DHCP messages and record IP
information of hosts. This feature cannot be enabled when DHCP relay is on. When this
feature is enabled, all the DHCP messages will be filterd through CPU and then be forwarded .
To make hosts abtain Ips through valid DHCP servers, DHCP snooping divide ports into trust
ones and untrust ones. Only messages from servers coming from the trust ports will be
forwarded. Thus invalid servers are kept off.
For security, DHCP snooping can limit the max number of hosts for a port or for a VLAN in
order to avoid animus attack.
4.3.1 Enable DHCP SNOOPING
By default, DHCP Snooping is disabled. Enable it in global configuration mode
Enable DHCP SNOOPING
dhcp-snooping
4.3.2 Configure trust ports
Specify some port as trust port.In general, vlaid servers are connected to the trust ports.
Specify port as trust port
dhcp-snooping trust
4.3.3 Configure max host number
With max host number specified for ports or VLAN, we can avoid animus hosts’ip abtian
attacktin by DOS and protect servers.
Configre port/VLAN max host number
dhcp-snooping max-clients num
4.3.4 Configure IP source guard
Prevent IP address stolen through IP source guard.
Configure interface IP source guard
ip-source-guard
4.3.5 IP source guard bind
After configuring IP source guard bind, the entry can get online without dhcp.

Содержание

Скачать