Qtech QSW-3900-48-SFP-DC Руководство пользователя v1-7 онлайн [161/245] 481613

Qtech QSW-3900-48-SFP-DC Руководство пользователя v1-7 онлайн [161/245] 481613
QTECH Software Configuration Manual
11-160
· Layer 2 switches can track DHCP client IP addresses through the DHCP snooping function, which
listens to DHCP broadcast packets.
When an unauthorized DHCP server exists in the network, a DHCP client may obtain an illegal IP address. To
ensure that the DHCP clients obtain IP addresses from valid DHCP servers, you can specify a port to be a trusted port
or an untrusted port through the DHCP snooping function.
· Trusted ports can be used to connect DHCP servers or ports of other switches. Untrusted ports can be
used to connect DHCP clients or networks.
· Trusted ports forward any received DHCP packet to ensure that DHCP clients can obtain IP addresses
from valid DHCP servers. Untrusted ports drop all the received packets.
Figure 1 illustrates a typical network diagram for DHCP snooping application, where Switch B is an QSW-3900
series switch.
Figure 1 Typical network diagram for DHCP snooping application
Figure 2 illustrates the interaction between a DHCP client and a DHCP server.
Figure 2 Interaction between a DHCP client and a DHCP server
DHCP snooping listens to the following two types of packets to retrieve the IP addresses the DHCP clients obtain
from DHCP servers and the MAC addresses of the DHCP clients :
· DHCP-ACK packet
· DHCP-REQUEST packet
For security, DHCP snooping can limit the max number of hosts for a port or for a VLAN in order to avoid

Содержание

Похожие устройства

Скачать