АМАТЕК AN-SGM28P24-400 [205/322] Fifteenth chapters

АМАТЕК AN-SGM28P24-400 [205/322] Fifteenth chapters
204 / 322
Fifteenth chapters
DHCP SNOOPING configuration
In the dynamic access network environment, the host obtains the IP address and the network
parameter through the DHCP server. DHCP SNOOPING is a kind of interception protocol for
ARP attack. By listening to the DHCP message, dynamically binding the DHCP server to the
client's IP address and the client's MAC address, so as to filter the ARP attack message on the
switch
switch support DHCP SNOOPING function, can effectively defend ARP attack. DHCP
SNOOPING listens to the DHCP message on the network and binds the port ARP information
You can configure four links to DHCP server physical ports, to some extent, to prevent
unknown server interference networks
When the switch power off restart, the binding table will be lost and need to be re learned;
switch provides binding table uploading and downloading function, and the binding table can be
stored in the TFTP server
This chapter describes the concept and configuration of DHCP SNOOPING, including the
following contents
DHCP SNOOPING introduce
DHCP SNOOPING configuration
DHCP SNOOPING configuration example
DHCP SNOOPING configuration error
15.1 DHCP SNOOPING introduce
Because of the simple trust mechanism, the ARP protocol has caused a loophole to the
network security. When a ARP attack message carrying a false MAC message arrives at the host,
it will override the local ARP cache table directly without restriction, leading to the normal data

Содержание

Похожие устройства

Скачать
Случайные обсуждения