Qtech QSW-8200-28T-AC — dHCP Snooping Commands User Manual for Network Management [65/79]

Превью страниц Страница 65 / 79
Qtech QSW-8200-28F-AC-DC [65/79] Ip dhcp snooping information option allow untrusted
User Manual
Chapter 5. Commands for DHCP Snooping 65
www.qtech.ru
resources of the switch, the actual number of trust users distributed depends on the
resource amount. If a bigger max number of users is set using this command, DHCP
Snooping will distribute the binding informaiton of untrust users to hardware to be
trust users as long as there is enough available resources. Otherwise, DHCP Snooping
will change the distributed binging informaiton accordint to the new smaller max user
number. When the number of distributed bingding informaiton entries reaches the max
limit, no new DHCP will be able to become trust user or to access other network
resouces via the switch.
Examples: Enable DHCP Snooping binding user funtion on Port ethernet1/0/1, setting
the max number of user allowed to access by Port Ethernet1/0/1 as 5.
Switch(Config-If-Ethernet1/0/1)# ip dhcp snooping binding user-control max-user 5
Related Command: ip dhcp snooping binding user-control
5.16 ip dhcp snooping information enable
Command: ip dhcp snooping information enable
no ip dhcp snooping information enable
Function: This command will enable option 82 function of DHCP Snooping on the
switch, the no operation of this command will disable that function.
Parameters: None.
Default Settings: Option 82 function is disabled in DHCP Snooping by default.
Command Mode: Global Configuration Mode.
Usage Guide: Only by implementing this command, can DHCP Snooping add standard
option 82 to DHCP request messages and forward the message. The format of option1
in option 82 (Circuit ID option) is standard vlan name plus physical port name, like
vlan1+ethernet1/0/12. That of option2 in option 82 (remote ID option) is CPU MAC of
the switch, like 00030f023301. If a DHCP request message with option 82 options is
received, DHCP Snooping will replace those options in the message with its own. If a
DHCP reply message with option 82 options is received, DHCP Snooping will dump
those options in the message and forward it.
Examples: Enable option 82 function of DHCP Snooping on the switch.
Switch(config)#ip dhcp snooping enable
Switch(config)# ip dhcp snooping binding enable
Switch(config)# ip dhcp snooping information enable
5.17 ip dhcp snooping information option allow-untrusted
Command: ip dhcp snooping information option allow-untrusted
no ip dhcp snooping information option allow-untrusted
Function: This command is used to set that allow untrusted ports of DHCP snooping to
receive DHCP packets with option82 option. When disabling this command, all
untrusted ports will drop DHCP packets with option82 option.

Содержание

Explore essential DHCP Snooping commands for managing network resources effectively. Learn how to configure user limits and enable option 82 for enhanced security.

Скачать