Qtech QSW-2900-24T4-AC [114/209] Dhcp snooping

Qtech QSW-2900-24T-AC [114/209] Dhcp snooping
6-112
6.9 DHCP snooping
6.9.1 Introduction to DHCP Snooping
For the sake of security, the IP addresses used by online DHCP clients need to be tracked for the administrator
to verify the corresponding relationship between the IP addresses the DHCP clients obtained from DHCP servers and
the MAC addresses of the DHCP clients.
· Layer 3 switches can track DHCP client IP addresses through a DHCP relay agent.
· Layer 2 switches can track DHCP client IP addresses through the DHCP snooping function, which
listens to DHCP broadcast packets.
When an unauthorized DHCP server exists in the network, a DHCP client may obtain an illegal IP address. To
ensure that the DHCP clients obtain IP addresses from valid DHCP servers, you can specify a port to be a trusted port
or an untrusted port through the DHCP snooping function.
· Trusted ports can be used to connect DHCP servers or ports of other switches. Untrusted ports can be
used to connect DHCP clients or networks.
· Trusted ports forward any received DHCP packet to ensure that DHCP clients can obtain IP addresses
from valid DHCP servers. Untrusted ports drop all the received packets.
Figure 4-1 illustrates a typical network diagram for DHCP snooping application, where Switch A is an QSW-2900
series switch.
Figure 4-1 Typical network diagram for DHCP snooping application
Figure 4-2 illustrates the interaction between a DHCP client and a DHCP server.

Содержание

Скачать